Cybersecurity

Cloudflare Adds Automated Remediation Policies for SaaS Application Risks Through CASB

Cloudflare has launched an automated remediation policy engine in CASB that responds as soon as risks are detected in SaaS applications, such as publicly accessible files, by revoking sharing or sending Webhooks to security tools. Currently supported actions begin with Microsoft and Google Workspace integrations, with a goal of completing remediation within five minutes or less.

2026-09-11
4 min read
9 views
فريق تحرير certi.news
Cloudflare Adds Automated Remediation Policies for SaaS Application Risks Through CASB

Cloudflare announced the addition of automated remediation policies to the Cloudflare CASB service, enabling security teams to define actions that are executed automatically when risks are detected in SaaS applications, rather than merely logging an alert and waiting for an administrator to intervene. Actions include revoking sharing for risky files and sending event details via Webhooks to operational platforms and channels selected by the organization.

From Alert to Action

CASB monitors the posture of SaaS applications for issues such as files whose sharing scope has been expanded, dormant administrative access keys or tokens, and OAuth applications with excessive permissions. Previously, these findings were primarily displayed as alerts or required manual remediation from the Cloudflare dashboard, leaving a time gap between discovering and fixing the issue.

The new policies allow an organization to define response logic once. When a new finding matches the policy conditions, CASB automatically executes the specified action. Cloudflare gives the example of an organization that blocks public file sharing while allowing exceptions for the marketing department; in this case, the policy can immediately revoke public sharing when it detects a file that violates the rule, instead of leaving the violation in a list awaiting individual review.

How Do the Policies Work?

The engine was built within the Cloudflare developer platform and uses Cloudflare Queues to place detected finding messages in a processing queue. A consumer running through Cloudflare Workers then checks for a matching policy and creates a task that is passed to the Cloudflare Workflows-based processing pipeline. Workflows provides resumable execution, with automatic retries when an operation fails or components are restarted.

Workflows also handles request-rate limits imposed by SaaS providers’ application programming interfaces; it can pause a task during the appropriate waiting period and then retry it instead of dropping it. Cloudflare sets a time target of no more than five minutes from detecting the finding to completing remediation.

Available Actions and Integrations

To create a policy, the customer specifies the relevant provider and integration or tenant, then selects the type of finding that will trigger the policy and the required action. Remediation and sending a Webhook can be combined. Native remediation performed directly by Cloudflare through a SaaS API includes actions for file and folder finding types in Microsoft and Google Workspace, and using it may require updating the integration permissions to read-write mode.

Webhooks can be directed to Slack, Microsoft Teams, Jira, ServiceNow, Tines, or any custom HTTP endpoint used by the organization. This makes it possible to connect CASB to a security operations center, a SOAR platform, or internal automation systems without building a separate event-remediation system.

Auditing and Current Limitations

Cloudflare records two types of logs within the Insights section of Cloudflare One. Admin Activity records who created, modified, or disabled the policy and when, while Cloud & SaaS Security policy logs record the outcome of each call, including the finding that triggered the policy, the affected file, the success or failure status, and errors such as 401 Unauthorized or rate-limit-exceeded responses.

In practice, these logs give the organization an audit trail linking a specific finding, such as a widely accessible file, to the automated action that remediated it and its timing. However, the scope of native remediation is currently still limited to file and folder finding types in Microsoft and Google Workspace, and some actions depend on granting the integration write permissions. Cloudflare says support for Custom Findings will be added during the following weeks, which may expand customers’ ability to define detection logic suited to their specific needs.

CASB Policies are available in the Cloud & SaaS findings section of the dashboard, and customers must connect or update a Microsoft 365 or Google Workspace integration with Read-Write permissions before creating their first remediation policy.

News source
Cloudflare Blog
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news