INTEGRITY Cloudflare Docs

Policy sharing

Organizations allows you to create security policies in one account and share them across other accounts in your Organization. This ensures consistent security posture across all accounts without manually duplicating configurations.

Policy sharing works the same way for both Enterprise and MSSP/Distributor Organizations.

In addition to WAF and Gateway policies, Organizations supports IdP federation, which lets you configure a single identity provider (such as Okta or Entra ID) in one account and share it across all accounts in your Organization. Shared IdP connections are read-only in recipient accounts and are automatically provisioned or removed as accounts join or leave the Organization.

Prerequisites

Policy sharing requires the appropriate product entitlements on the accounts involved. Organizations does not grant access to WAF or Gateway features — your accounts must already have the required SKUs.

WAF policy sharing

Create WAF custom rulesets in one account and share them to other accounts within your Organization.

How it works

  1. Create a WAF custom ruleset in a source account — this is the account where you author and manage the rules.
  2. Share the ruleset to one or more destination accounts within your Organization.
  3. The shared ruleset appears in the destination accounts as a read-only policy.
  4. Changes made to the ruleset in the source account automatically propagate to all destination accounts.

Key behaviors

Share a WAF custom ruleset

  1. In the source account, go to Security > WAF > Custom rules.
  2. Create or select a custom ruleset.
  3. Select Share to Organization.
  4. Choose the destination accounts.
  5. Select Share.

The shared ruleset now appears in the destination accounts under their WAF custom rules.

Gateway policy sharing

Share Zero Trust Gateway policies across accounts in your Organization. Gateway policy sharing supports the following policy types:

How it works

  1. Create a Gateway policy in a source account.
  2. Share the policy to one or more destination accounts within your Organization.
  3. The shared policy appears in the destination accounts as a read-only policy.
  4. Changes made to the policy in the source account automatically propagate to all destination accounts.

Key behaviors

Manage shared policies

View shared policies

From the Organization overview, you can see which policies are shared and to which accounts. Shared policies are marked with a sharing indicator in the destination account's policy list.

Remove a shared policy

To stop sharing a policy with a destination account:

  1. In the source account, go to the shared policy.
  2. Select Manage sharing.
  3. Remove the destination account from the sharing list.

The policy is immediately removed from the destination account.

Best practices