What’s new?
Cloudflare announced that its Cloudflare Access Security Broker (CASB) now supports API‑based remediation policies. When a security finding is detected in a supported SaaS integration, the policy can either invoke a first‑party remediation action or push the finding to a webhook endpoint.
Automatic remediation for Microsoft 365 and Google Workspace
The feature currently works for file‑sharing findings in both Microsoft 365 and Google Workspace. Once a policy triggers, Cloudflare calls the respective SaaS API to revoke the external‑sharing configuration that caused the finding, eliminating the need for a human to intervene.
Webhook integration
In addition to remediation, a policy can forward the finding data to Slack, ServiceNow, or any custom webhook destination. Webhook actions are available for all posture finding types across CASB integrations, and a single policy can combine remediation and webhook delivery.
How to create a CASB remediation policy
- Open Cloudflare One and navigate to
Cloud & SaaS findings > Policies. - Click Create a policy and provide a name and optional description.
- Select the vendor, integration, and finding type that should trigger the policy.
- Choose one or both actions: Run Remediation or Send webhooks.
- Enable the policy and save.
What’s next?
Cloudflare notes that support for additional finding types and SaaS integrations is “coming soon.” Users can follow the official documentation for a full list of currently supported findings.