logo

RDP without the risk: Cloudflare's browser-based solution for secure third-party access

ID: ab93b092-21a1-5f8f-a47a-9067471f70f6

STIX ID: report--ab93b092-21a1-5f8f-a47a-9067471f70f6

Feed Name: Cloudflare Blog

Date Published: 2025-03-21

Date Updated: 2026-04-27

Author: Ann Ming Samborski

...
...

Cloudflare announces a clientless, browser-based RDP capability in Cloudflare Access that secures Windows server access with Zero Trust controls, leveraging IronRDP in the browser over TLS WebSockets, Cloudflare Workers as a proxy, Apollo for routing, and Oxy for policy enforcement and logging. The post outlines RDP’s historical security challenges (e.g., BlueKeep, credential abuse), how the architecture mitigates them via SSO/MFA, JWT-based authorization, and modern authentication, and highlights benefits like no additional software, low latency, and integrated auditing. It previews roadmap items such as DLP controls and passwordless authentication and notes plans for FedRAMP High inclusion, with the feature currently in closed beta.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.