OFICIAL Cloudflare Blog

Introducing automatic remediation policies with Cloudflare CASB

What happened
Based on Cloudflare Blog · Sep 11, 2026

Cloudflare introduces automatic remediation policies for its CASB tool, enabling security teams to configure instant, event-driven responses to SaaS misconfigurations without manual intervention.

Introducing automatic remediation policies with Cloudflare CASB
Cloudflare Blog — Cloudflare
Key points
·
Cloudflare CASB now offers automatic remediation policies to revoke risky file shares or dispatch webhooks without manual intervention.
·
Policies execute within five minutes of detection, using Cloudflare Workflows for fault-tolerant, rate-limited API retries.
·
Admin Activity and Cloud & SaaS Security policy logs provide audit trails and runtime outcomes for compliance and troubleshooting.

Cloudflare CASB now supports automatic remediation policies, allowing security teams to define event-driven logic that revokes risky file shares or dispatches webhooks immediately upon detecting a misconfiguration. This builds on the tool’s existing passive monitoring capabilities, which surface risks such as overshared files, dormant admin keys, and OAuth apps with excessive permissions across SaaS applications like Google Workspace and Microsoft 365. Previously, manual remediation required logging into multiple SaaS portals, but the new policies automate responses, reducing the window between detection and resolution from hours or days to minutes.

The automation engine, integrated into Cloudflare One, executes predefined actions such as revoking file access or forwarding events to a SOC or SOAR platform the moment a finding is detected. For example, organizations can automatically revoke public file shares that violate policy, eliminating the need for administrators to manually address each instance in a growing backlog of findings. Policies can combine remediation actions with webhook notifications, providing flexibility to use native CASB capabilities or integrate with existing internal automation systems.

Cloudflare’s architecture for CASB policies relies on the Cloudflare developer platform, using Cloudflare Queue and Workers to process findings and execute remediation jobs via Cloudflare Workflows. This ensures durable, fault-tolerant execution with automatic retries for API rate limits, aiming for a target of five minutes or less from detection to completed remediation. Each policy generates two types of logs: Admin Activity logs for policy changes and Cloud & SaaS Security policies logs for runtime outcomes, including success or failure details and specific errors.

Customers can access CASB Policies in the Cloud & SaaS findings section of the Cloudflare dashboard, requiring Microsoft 365 or Google Workspace integration with Read-Write permissions to create policies. Support for Custom Findings will be added in the coming weeks, allowing organizations to define or augment detection logic. Cloudflare offers 50 free seats for new Cloudflare One users to get started with CASB, with additional deployment options available for larger-scale needs.

Original source → Deals on Clipraptor.com →