Lộ trình đang học Current learning path

Cloudflare One Cloudflare One

Bảo vệ users, access, SaaS và networks. Secure users, access, SaaS, and networks.

Về trang lộ trình Track home

Phần 2: ZTNA — thay thế VPN từng bước Part 2: ZTNA — replace VPN step by step · Bài 1/2 Lesson 1/2

Kết nối Identity Provider Connect your Identity Provider

Tích hợp Google Workspace, Azure AD hoặc Okta. Bật MFA ở IdP trước khi enforce policy trên Cloudflare. Integrate Google Workspace, Azure AD, or Okta. Enable MFA at the IdP before enforcing Cloudflare policies.

Các bước thực hiện Step-by-step

  1. Zero Trust → Settings → Authentication → Add IdP. Zero Trust → Settings → Authentication → Add IdP.
  2. Chọn Google / Azure / Okta — làm theo wizard OAuth/SAML. Choose Google / Azure / Okta — follow OAuth/SAML wizard.
  3. Test login flow với admin account. Test login flow with an admin account.
  4. Bật MFA bắt buộc tại IdP trước Access policy. Require MFA at IdP before Access policies.

Giải thích chi tiết Detailed explanation

Access tin IdP của bạn — MFA tại IdP là lớp bảo mật quan trọng nhất. Access trusts your IdP — MFA at the IdP is the most important security layer.

Lưu ý (best practices) Note (best practices)

Rule group có thể gom yêu cầu device posture và email cụ thể, hoặc tham chiếu group trong IdP — giúp policy dễ maintain hơn rule từng user. Rule groups can combine device posture requirements and specific emails, or reference an IdP group — easier to maintain than per-user rules.

Nguồn: Source: Access application — Best practices Access application — Best practices

Ví dụ triển khai (Cloudflare Resources) Deployment examples (Cloudflare Resources)

Ví dụ chính thức từ Cloudflare Resources — gợi ý theo chủ đề bài học trong lộ trình này. Official examples from Cloudflare Resources — matched to this lesson within this path.

Tutorial Tutorial Cloudflare One Cloudflare One

Send SSO attributes to Access-protected origins với Workers Send SSO attributes to Access-protected origins with Workers

Tóm tắt thực hành: Send SSO attributes to Access-protected origins với Workers trên Cloudflare One (Zero Trust). This tutorial will walk you through extending the single-sign-on (SSO) capabilities of Cloudflare Access with our serverless computing platform, Cloudflare Workers.

This tutorial will walk you through extending the single-sign-on (SSO) capabilities of Cloudflare Access with our serverless computing platform, Cloudflare Workers.

Tìm hiểu thêm Learn more
Tutorial Tutorial Cloudflare One Cloudflare One

Truy cập clientless tới DNS private qua Cloudflare Access Access a web application via its private hostname without the Cloudflare One Client

Tóm tắt thực hành: Access web ứng dụng via its private hostname without Cloudflare One Client trên Cloudflare One (Zero Trust). With Cloudflare Browser Isolation and resolver policies, users can connect to private web-based applications via their private hostnames.

With Cloudflare Browser Isolation and resolver policies, users can connect to private web-based applications via their private hostnames.

Tìm hiểu thêm Learn more
Tutorial Tutorial Cloudflare One Cloudflare One

Access và secure MySQL cơ sở dữ liệu using Cloudflare Tunnel và network policies Access and secure a MySQL database using Cloudflare Tunnel and network policies

Tóm tắt thực hành: Access và secure MySQL cơ sở dữ liệu using Cloudflare Tunnel và network policies trên Cloudflare One (Zero Trust). Using Cloudflare Tunnel's private networks, users can connect to arbitrary non-browser based TCP/UDP applications, like databases. You can set up network policies that implement z…

Using Cloudflare Tunnel's private networks, users can connect to arbitrary non-browser based TCP/UDP applications, like databases. You can set up network policies that implement zero trust controls to define who and what can access those applications using the Cloudflare One Client.

Tìm hiểu thêm Learn more
Tutorial Tutorial Cloudflare One Cloudflare One

Xây dựng API to access D1 using proxy Worker Build an API to access D1 using a proxy Worker

This tutorial shows how to create an API that allows you to securely run queries against a cơ sở dữ liệu D1. The API can be used to customize access controls and/or limit what tables can be queried.

This tutorial shows how to create an API that allows you to securely run queries against a D1 database. The API can be used to customize access controls and/or limit what tables can be queried.

Tìm hiểu thêm Learn more

Xem thêm ví dụ trong lộ trình → More examples in this path →

Tài liệu Cloudflare Developers Cloudflare Developer docs

Sản phẩm liên quan Related products

Học xong hoặc muốn đổi hướng? Finished or want a different path?

Ba lộ trình độc lập — mỗi lộ trình chỉ gồm bài học và tài liệu trong phạm vi đó. Chọn lộ trình khác khi sẵn sàng, không cần học song song. Three independent paths — each includes only lessons and materials for that scope. Switch when you are ready; no need to study paths in parallel.

Chưa chắc — làm bài chọn lộ trình Not sure — use the path selector · So sánh cả ba lộ trình Compare all three paths