Cloudflare launches API‑based CASB remediation policies for Microsoft 365 and Google Workspace

What’s new?

Cloudflare announced that its Cloudflare Access Security Broker (CASB) now supports API‑based remediation policies. When a security finding is detected in a supported SaaS integration, the policy can either invoke a first‑party remediation action or push the finding to a webhook endpoint.

Automatic remediation for Microsoft 365 and Google Workspace

The feature currently works for file‑sharing findings in both Microsoft 365 and Google Workspace. Once a policy triggers, Cloudflare calls the respective SaaS API to revoke the external‑sharing configuration that caused the finding, eliminating the need for a human to intervene.

Webhook integration

In addition to remediation, a policy can forward the finding data to Slack, ServiceNow, or any custom webhook destination. Webhook actions are available for all posture finding types across CASB integrations, and a single policy can combine remediation and webhook delivery.

How to create a CASB remediation policy

  1. Open Cloudflare One and navigate to Cloud & SaaS findings > Policies.
  2. Click Create a policy and provide a name and optional description.
  3. Select the vendor, integration, and finding type that should trigger the policy.
  4. Choose one or both actions: Run Remediation or Send webhooks.
  5. Enable the policy and save.

What’s next?

Cloudflare notes that support for additional finding types and SaaS integrations is “coming soon.” Users can follow the official documentation for a full list of currently supported findings.