# New Accounts Get Cloudflare's Own IdP by Default!

Hi there, it's me, Shii-chan! Today's change is small, but it smooths out that very first stumble, so I'm happy to share it.

## What was announced?

On Cloudflare's Changelog, there's news that the **default login method** for new Zero Trust organizations has changed. Until now, newly created organizations defaulted to one-time PIN (OTP), but going forward the default is the [Cloudflare identity provider](https://developers.cloudflare.com/cloudflare-one/integrations/identity-providers/cloudflare/).

## The story so far

Until now, when you created a new Zero Trust organization, the first login method was [one-time PIN (OTP)](https://developers.cloudflare.com/cloudflare-one/integrations/identity-providers/one-time-pin/). You type in a PIN sent to your email, so it works fine, but it was one extra step.

## What changes

From now on, new accounts can sign in **with their existing Cloudflare account credentials**, no extra setup needed, so you can get going right away. Authentication is limited to members of your account, so only your own people can get in.

## Dive Deep

A few details worth knowing:

- This applies to **newly created accounts only**. Existing organizations keep their current login methods and won't switch automatically.
- If you want to use this IdP on an existing account, you need to enable it manually.
- You keep your flexibility: you can still add OTP later or connect [third-party identity providers](https://developers.cloudflare.com/cloudflare-one/integrations/identity-providers/).

## Wrap-up

- The default login for **new Zero Trust organizations** changed from OTP to the Cloudflare identity provider.
- New accounts can sign in with existing Cloudflare credentials, making first-time setup easier.
- New accounts only; existing orgs enable it manually, and OTP and third-party IdPs still work.

This one is a nice fit for anyone just starting out with Cloudflare One, smoothing the on-ramp!
