Module 1 — Account Setup
Goal: Create your Cloudflare account, run the Cloudflare One setup, choose your permanent team name, confirm your login works, and add a backup administrator.
| 👤 Who does this | IT / Identity administrator |
| ⏱️ Time | ~30 minutes |
| 🎯 You'll finish with | A live Cloudflare One (Zero Trust) organization at https://<team-name>.cloudflareaccess.com that you can already log in to |
| ✋ Before you begin | A work email, billing details, and your chosen team name (from the prerequisites checklist) |
💡 If you already have a Cloudflare account, skip to Part B.
First, three words you'll see everywhere
Before you click anything, here's the vocabulary — it removes 90% of the confusion later.
| Term | Plain meaning | Example |
|---|---|---|
| Account | Your billing + admin container in Cloudflare. Holds domains, settings, and members. | "Acme Corp" account |
| Team / organization | Your Cloudflare One (Zero Trust) instance inside that account. | Acme's Zero Trust org |
| Team name | The short, unique label you pick for your team. It becomes your login URL. | acme |
| Team domain | The URL built from your team name, where users sign in and reach secured apps. | acme.cloudflareaccess.com |
📺 The two dashboards you'll use:
- Account dashboard —
https://dash.cloudflare.com— billing, members, domains (account-wide things).- Cloudflare One dashboard —
https://dash.cloudflare.com/one/(also reachable via Zero Trust in the sidebar) — everything Zero Trust: identity, devices, Access, Gateway, DLP, etc.This guide tells you which one you're in at each step.
Part A — Create your Cloudflare account
Step 1 — Sign up
- 👉 Open a browser and go to
https://dash.cloudflare.com/sign-up - ⌨️ Enter your work email and a strong password.
- 👉 Click Sign Up.
📺 What you'll see: A confirmation that your account was created, and a verification email in your inbox.
Step 2 — Verify your email
- 👉 Open the email from Cloudflare ("Verify your email address").
- 👉 Click the verification link.
⚠️ Watch out: Some later actions (like inviting members) require a verified email. Don't skip this.
✅ Checkpoint: You're signed in on the Cloudflare dashboard home page. If it prompts you to "add a website," you can ignore that — Zero Trust doesn't require a domain to start.
Step 3 — Turn on two-factor authentication (do this now)
- 👉 Top-right corner → click your profile icon → My Profile.
- 👉 Open the Authentication tab.
- 👉 Under Two-Factor Authentication, click Add and follow the prompts to set up an authenticator app.
⚠️ Watch out: Because Cloudflare is now the default login method for new Zero Trust orgs (Part C), your Cloudflare account security is your Zero Trust security. Protecting this account with 2FA is not optional — do it before going further.
Part B — Run the Cloudflare One setup
Step 4 — Open Cloudflare One
- 👉 In the dashboard's left menu, click Zero Trust (this opens the Cloudflare One dashboard).
(Or go directly to
https://dash.cloudflare.com/one/.)
📺 What you'll see: The Cloudflare One onboarding/setup screen, asking you to choose a team name and select a plan.
Step 5 — Choose your team name ⚠️ this is permanent
- ⌨️ Enter your chosen team name (e.g.
acme). Use lowercase letters, numbers, and hyphens only. - 👉 Click Next.
📺 What this means: Your organization's sign-in URL is now https://acme.cloudflareaccess.com (replace acme with yours). Users hit this URL to sign in and to reach the apps you secure. You'll also enter the team name when enrolling devices in Module 3.
⚠️ Watch out: Changing the team name later breaks every saved login URL, app configuration, and device enrollment. Choose a name you'll keep — usually your company's short name. You can view (and, with care, change) it later under Cloudflare One → Settings.
✅ Checkpoint: Write your team domain here so you have it for every later module:
https://________________.cloudflareaccess.com
Step 6 — Choose a plan
- 👉 Select your plan:
- Free — great for evaluating and for Modules 1–5 (up to 50 seats/users).
- Pay-as-you-go — per-seat billing beyond the free tier.
- Enterprise — required for DLP (Module 6), advanced AI controls (Module 7), advanced device posture, and Cloudflare WAN (Module 8). Enterprise is arranged with your Cloudflare account team.
- 👉 Click Next / Proceed to payment.
- ⌨️ Enter your billing/payment details and confirm.
💡 Tip: A payment method is required even on Free — you will not be charged on the Free plan. A "seat" is consumed by each user who authenticates or enrolls a device; you can see seat usage later under Cloudflare One → Settings → Account.
✅ Checkpoint: You land on the Cloudflare One Overview page (URL contains /one/). This is the dashboard you'll use for every remaining module. 🎉
Part C — Your login already works (Cloudflare as your default identity provider)
Here's the big time-saver for new accounts: when you create a new Zero Trust organization, Cloudflare automatically sets itself up as your default identity provider. That means your team can sign in with their existing Cloudflare account credentials — no one-time PINs, no third-party setup, nothing to configure to get started. (This replaced One-time PIN as the default in 2026.)
You'll connect your corporate identity provider (Entra ID / Okta / Google) in Module 2 for real production use — but you can already test that authentication works right now.
Step 7 — See your default login method
- 👉 In Cloudflare One, go to Settings → Authentication (or Integrations → Identity providers).
- 📺 What you'll see: Cloudflare already listed under Login methods / Your identity providers — added for you automatically.
Step 8 — (Recommended) Restrict logins to your account members
By default, any Cloudflare user could authenticate against the Cloudflare login method. Tighten this:
- 👉 Click the Cloudflare identity provider.
- 👉 Enable Restrict to account members — now only users who are members of your Cloudflare account can authenticate this way.
- 👉 Click Save.
💡 Tip: You'll add real employees as account members in Part E and Module 2. For contractors/externals, you can also enable One-time PIN (email code) as an additional method — Cloudflare login and OTP can run side by side so users choose.
Step 9 — Test the sign-in experience
- 👉 Open a private/incognito browser window and go to your team domain:
https://acme.cloudflareaccess.com(use your team name). - 📺 What you'll see: Your organization's sign-in page, offering Cloudflare as a login method.
- 👉 Sign in with your Cloudflare account.
✅ Checkpoint: You can authenticate at your team domain. Your Zero Trust org is live and usable before you've even connected a corporate IdP. 🎉
Part D — Confirm your team name and tour key settings
Step 10 — Confirm team name and domain
- 👉 In Cloudflare One, go to Settings → Custom Pages (or Settings → Account / General, depending on your dashboard version).
- 📺 What you'll see: Your Team domain shown as
<team-name>.cloudflareaccess.com.
✅ Checkpoint: It matches what you wrote down in Step 5.
Step 11 — Quick tour: the settings you'll return to
You don't need to change these now — just know where they live:
| Setting | Where | You'll use it in |
|---|---|---|
| Team name / domain | Settings → Custom Pages / Account | This module |
| Authentication (login methods) | Settings → Authentication · Integrations → Identity providers | Module 2 |
| WARP Client / device settings | Settings → WARP Client | Module 3 |
| Custom Pages (branded login/block pages) | Settings → Custom Pages | Before go-live |
| Network / TLS decryption | Settings → Network | Module 6 |
| Logs / Logpush | Logs → Logpush | Step 13 |
💡 Tip: Brand your login and block pages (Settings → Custom Pages) before rolling out to users — it builds trust and cuts "is this real?" helpdesk tickets.
Part E — Add administrators and a break-glass account
Right now you're the only administrator. Add a backup so a future misconfiguration can never lock your whole org out.
Step 12 — Add a second Super Administrator
- 👉 Switch to the account dashboard:
https://dash.cloudflare.com - 👉 Top-right → profile icon → Manage Account → Members.
- 👉 Click Invite.
- ⌨️ Enter a trusted colleague's email (or a shared, secured IT break-glass mailbox).
- 👉 Choose the role Super Administrator - All Privileges.
- 👉 Click Continue to summary → Invite.
📺 What you'll see: The person appears in the Members list as Pending until they accept the emailed invitation.
✅ Checkpoint: The Members list shows at least two Super Administrators (you + the backup).
⚠️ Watch out: Store the break-glass account's credentials somewhere safe and separate (a password manager / vault). If you ever lock yourself out with a policy, this is how you get back in.
👥 Need more than a couple of admins, or want to split duties (billing vs. security vs. read-only)? Roles, invitations vs. Direct Add, user groups, account-owned API tokens, and Organizations are all covered in the companion page: 1b — Account administration & roles.
Part F — Turn on logging (so you can see what's happening)
- 👉 In Cloudflare One, go to Logs → Logpush (or Settings → Logs).
- 💡 If you have a SIEM or log store (Splunk, S3, Cloudflare R2, etc.), click Add a Logpush job and follow the prompts to stream Access and Gateway logs to it. If you don't have one yet, you can still view logs in the dashboard — note this to set up before go-live.
✅ Checkpoint: Either a Logpush job exists, or you've noted to set it up before go-live.
✅ Module 1 complete!
You now have:
- ✅ A secure Cloudflare account with 2FA
- ✅ A live Cloudflare One (Zero Trust) organization
- ✅ Your permanent team domain:
https://<team-name>.cloudflareaccess.com - ✅ A working login (Cloudflare as default IdP), optionally restricted to account members
- ✅ A backup Super Administrator (break-glass)
Quick troubleshooting
| Problem | Fix |
|---|---|
| Didn't get the verification email | Check spam; on the sign-in page click Resend verification |
| "Add a website" keeps prompting | Ignore it — Zero Trust doesn't require a domain. Click Zero Trust in the sidebar to continue |
| Can't invite members | You must be a Super Administrator with a verified email — verify your email (Step 2) |
| Greyed-out plan features | Some features need Enterprise (DLP, Cloudflare WAN); that's expected on Free — continue and upgrade later |
| Anyone with a Cloudflare account can sign in | Enable Restrict to account members on the Cloudflare identity provider (Step 8) |
| Can't find Settings in Cloudflare One | Scroll to the bottom of the left menu; on narrow screens use the ☰ menu icon |
👉 Next: Module 1b — Account Administration & Roles (optional deep-dive)
Or skip straight to Module 2 — Identity Provider to connect your corporate login.