Identity-aware filtering with no client! Gateway Authorization Proxy is now GA
Hiya, it's me, Shii-chan! Today I've got a small-but-handy update from the Cloudflare One filtering world.
Cloudflare ChangelogWhat was announced?
On the Cloudflare Changelog (Gateway category), Gateway Authorization Proxy and hosted PAC files have moved from limited access to general availability (GA) for all plan types.
Both features are about applying Gateway filtering even when you can't install a dedicated client on the device.
The story so far
Until now, getting per-user Gateway policies to apply reliably mostly meant installing the Cloudflare One Client on the endpoint.
But some environments make that hard. The post calls out virtual desktops (VDI) and compliance-restricted endpoints as examples. In those places, filtering based on "who is accessing" was tricky.
What changes
With Gateway Authorization Proxy, you can use Cloudflare Access authentication to identify users before applying Gateway policies. The key point is that you get identity-aware filtering without installing the Cloudflare One Client.
For hosted PAC files, you can now create and distribute PAC files directly from Cloudflare One on Cloudflare's global network, so you no longer need to host the file yourself. That makes distribution much simpler.
Dive Deep
This announcement is mainly the GA news, and it doesn't spell out detailed setup steps, limits, or pricing. If you want to follow the configuration, the proxy endpoints documentation is the place to go — it covers the authorization endpoint and how to create a hosted PAC file.
Wrap-up
- Gateway Authorization Proxy and hosted PAC files are now GA on all plans
- You get identity-based filtering via Cloudflare Access auth, without installing a client
- PAC files can be distributed straight from Cloudflare's network — no self-hosting needed
- A welcome update for admins managing VDI or compliance-restricted endpoints where clients are hard to install