-
Notifications
You must be signed in to change notification settings - Fork 6.5k
New reference architecture for Cloudflare One and SentinelOne #22022
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: production
Are you sure you want to change the base?
New reference architecture for Cloudflare One and SentinelOne #22022
Conversation
Howdy and thanks for contributing to our repo. The Cloudflare team reviews new, external PRs within two (2) weeks. If it's been two weeks or longer without any movement, please tag the PR Assignees in a comment. We review internal PRs within 1 week. If it's something urgent or has been sitting without a comment, start a thread in the Developer Docs space internally. PR Change SummaryIntroduced a new reference architecture for integrating Cloudflare One with SentinelOne, enhancing security posture through device-based access policies.
Added Files
How can I customize these reviews?Check out the Hyperlint AI Reviewer docs for more information on how to customize the review. If you just want to ignore it on this PR, you can add the Note specifically for link checks, we only check the first 30 links in a file and we cache the results for several hours (for instance, if you just added a page, you might experience this). Our recommendation is to add |
@@ -0,0 +1,178 @@ | |||
--- | |||
title: Enhancing security posture with SentinelOne and Cloudflare One |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The article text uses the term "Cloudflare Zero Trust" instead of "Cloudflare One" (e.g. line 19). Should we change the title to match?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
That works
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The reason Cloudflare One is used, is because the product team are moving towards Cloudflare One as the branding and not Zero Trust. VB, you need to reflect that in this document. The document should talk about Cloudflare One not Cloudflare Zero Trust.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Suggested a few places below where it makes sense to use Cloudflare One terminology.
src/content/docs/reference-architecture/architectures/cloudflare-sase-with-sentinelone.mdx
Outdated
Show resolved
Hide resolved
src/content/docs/reference-architecture/architectures/cloudflare-sase-with-sentinelone.mdx
Outdated
Show resolved
Hide resolved
src/content/docs/reference-architecture/architectures/cloudflare-sase-with-sentinelone.mdx
Outdated
Show resolved
Hide resolved
src/content/docs/reference-architecture/architectures/cloudflare-sase-with-sentinelone.mdx
Outdated
Show resolved
Hide resolved
src/content/docs/reference-architecture/architectures/cloudflare-sase-with-sentinelone.mdx
Outdated
Show resolved
Hide resolved
src/content/docs/reference-architecture/architectures/cloudflare-sase-with-sentinelone.mdx
Outdated
Show resolved
Hide resolved
src/content/docs/reference-architecture/architectures/cloudflare-sase-with-sentinelone.mdx
Outdated
Show resolved
Hide resolved
src/content/docs/reference-architecture/architectures/cloudflare-sase-with-sentinelone.mdx
Outdated
Show resolved
Hide resolved
src/content/docs/reference-architecture/architectures/cloudflare-sase-with-sentinelone.mdx
Outdated
Show resolved
Hide resolved
src/content/docs/reference-architecture/architectures/cloudflare-sase-with-sentinelone.mdx
Outdated
Show resolved
Hide resolved
src/content/docs/reference-architecture/architectures/cloudflare-sase-with-sentinelone.mdx
Outdated
Show resolved
Hide resolved
src/content/docs/reference-architecture/architectures/cloudflare-sase-with-sentinelone.mdx
Outdated
Show resolved
Hide resolved
src/content/docs/reference-architecture/architectures/cloudflare-sase-with-sentinelone.mdx
Outdated
Show resolved
Hide resolved
src/content/docs/reference-architecture/architectures/cloudflare-sase-with-sentinelone.mdx
Outdated
Show resolved
Hide resolved
src/content/docs/reference-architecture/architectures/cloudflare-sase-with-sentinelone.mdx
Outdated
Show resolved
Hide resolved
src/content/docs/reference-architecture/architectures/cloudflare-sase-with-sentinelone.mdx
Outdated
Show resolved
Hide resolved
src/content/docs/reference-architecture/architectures/cloudflare-sase-with-sentinelone.mdx
Outdated
Show resolved
Hide resolved
src/content/docs/reference-architecture/architectures/cloudflare-sase-with-sentinelone.mdx
Outdated
Show resolved
Hide resolved
src/content/docs/reference-architecture/architectures/cloudflare-sase-with-sentinelone.mdx
Outdated
Show resolved
Hide resolved
src/content/docs/reference-architecture/architectures/cloudflare-sase-with-sentinelone.mdx
Outdated
Show resolved
Hide resolved
src/content/docs/reference-architecture/architectures/cloudflare-sase-with-sentinelone.mdx
Outdated
Show resolved
Hide resolved
src/content/docs/reference-architecture/architectures/cloudflare-sase-with-sentinelone.mdx
Outdated
Show resolved
Hide resolved
src/content/docs/reference-architecture/architectures/cloudflare-sase-with-sentinelone.mdx
Outdated
Show resolved
Hide resolved
src/content/docs/reference-architecture/architectures/cloudflare-sase-with-sentinelone.mdx
Outdated
Show resolved
Hide resolved
src/content/docs/reference-architecture/architectures/cloudflare-sase-with-sentinelone.mdx
Outdated
Show resolved
Hide resolved
## Related resources | ||
|
||
- [Overview of SentinelOne and Cloudflare partnership](https://www.cloudflare.com/partners/technology-partners/sentinelone/) | ||
- [Overview of Microsoft and Cloudflare partnership](https://www.cloudflare.com/partners/technology-partners/microsoft/) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
how does Microsoft relate to SentinelOne?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
We will need to remove this, It is from previous architecture.
products: | ||
- Access | ||
- Gateway | ||
- CASB |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Remove CASB and Email Security since they are not mentioned in the article.
Add Zero Trust WARP Client
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Sure
src/content/docs/reference-architecture/architectures/cloudflare-sase-with-sentinelone.mdx
Outdated
Show resolved
Hide resolved
src/content/docs/reference-architecture/architectures/cloudflare-sase-with-sentinelone.mdx
Outdated
Show resolved
Hide resolved
src/content/docs/reference-architecture/architectures/cloudflare-sase-with-sentinelone.mdx
Outdated
Show resolved
Hide resolved
…re-sase-with-sentinelone.mdx
src/content/docs/reference-architecture/architectures/cloudflare-sase-with-sentinelone.mdx
Outdated
Show resolved
Hide resolved
src/content/docs/reference-architecture/architectures/cloudflare-sase-with-sentinelone.mdx
Outdated
Show resolved
Hide resolved
src/content/docs/reference-architecture/architectures/cloudflare-sase-with-sentinelone.mdx
Outdated
Show resolved
Hide resolved
…re-sase-with-sentinelone.mdx
…re-sase-with-sentinelone.mdx
src/content/docs/reference-architecture/architectures/cloudflare-sase-with-sentinelone.mdx
Outdated
Show resolved
Hide resolved
…re-sase-with-sentinelone.mdx
|
||
## Introduction | ||
|
||
The integration between Cloudflare Zero Trust and SentinelOne provides organizations with a comprehensive security solution that combines endpoint protection with [Zero Trust Network Access](https://www.cloudflare.com/learning/security/glossary/what-is-zero-trust/). This integration enables organizations to make access decisions based on device security posture, ensuring that only healthy and compliant devices can access protected resources. This reference architecture describes how organizations can implement and leverage this integration to enhance their security posture. The integration can assist in advancing an organization's or agency's Zero Trust Architecture Maturity Model, with the goal of one's organization eventually achieving Advanced or Optimal across all [CISA's 5 Pillars of Zero Trust.](https://www.cisa.gov/sites/default/files/2023-04/CISA_Zero_Trust_Maturity_Model_Version_2_508c.pdf) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The integration between Cloudflare Zero Trust and SentinelOne provides organizations with a comprehensive security solution that combines endpoint protection with [Zero Trust Network Access](https://www.cloudflare.com/learning/security/glossary/what-is-zero-trust/). This integration enables organizations to make access decisions based on device security posture, ensuring that only healthy and compliant devices can access protected resources. This reference architecture describes how organizations can implement and leverage this integration to enhance their security posture. The integration can assist in advancing an organization's or agency's Zero Trust Architecture Maturity Model, with the goal of one's organization eventually achieving Advanced or Optimal across all [CISA's 5 Pillars of Zero Trust.](https://www.cisa.gov/sites/default/files/2023-04/CISA_Zero_Trust_Maturity_Model_Version_2_508c.pdf) | |
The integration between Cloudflare One and SentinelOne provides organizations with a comprehensive security solution that combines endpoint protection with [Zero Trust Network Access](https://www.cloudflare.com/learning/security/glossary/what-is-zero-trust/). This integration enables organizations to make access decisions based on device security posture, ensuring that only healthy and compliant devices can access protected resources. This reference architecture describes how organizations can implement and leverage this integration to enhance their security posture. The integration can assist in advancing an organization's or agency's Zero Trust Architecture Maturity Model, with the goal of one's organization eventually achieving Advanced or Optimal across all [CISA's 5 Pillars of Zero Trust.](https://www.cisa.gov/sites/default/files/2023-04/CISA_Zero_Trust_Maturity_Model_Version_2_508c.pdf) |
|
||
## Integration overview | ||
|
||
Cloudflare Zero Trust can integrate with SentinelOne to enforce device-based access policies for applications and resources. The integration works through a service-to-service posture check that identifies devices based on their serial numbers. This allows organizations to ensure that only managed and secure devices can access sensitive resources. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Cloudflare Zero Trust can integrate with SentinelOne to enforce device-based access policies for applications and resources. The integration works through a service-to-service posture check that identifies devices based on their serial numbers. This allows organizations to ensure that only managed and secure devices can access sensitive resources. | |
Cloudflare One can integrate with SentinelOne to enforce device-based access policies for applications and resources. The integration works through a service-to-service posture check that identifies devices based on their serial numbers. This allows organizations to ensure that only managed and secure devices can access sensitive resources. |
- Bandwidth and latency requirements for posture checks | ||
- Integration with existing security tools and workflows | ||
|
||
The integration between Cloudflare Zero Trust and SentinelOne requires thoughtful planning to ensure successful implementation. At its foundation, organizations need to prepare their environment by having the SentinelOne agent and Cloudflare WARP client deployed on all devices that will be subject to posture checks. This foundational step ensures that both security monitoring and secure network connectivity are in place before building additional security controls. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The integration between Cloudflare Zero Trust and SentinelOne requires thoughtful planning to ensure successful implementation. At its foundation, organizations need to prepare their environment by having the SentinelOne agent and Cloudflare WARP client deployed on all devices that will be subject to posture checks. This foundational step ensures that both security monitoring and secure network connectivity are in place before building additional security controls. | |
The integration between Cloudflare One and SentinelOne requires thoughtful planning to ensure successful implementation. At its foundation, organizations need to prepare their environment by having the SentinelOne agent and Cloudflare WARP client deployed on all devices that will be subject to posture checks. This foundational step ensures that both security monitoring and secure network connectivity are in place before building additional security controls. |
|
||
## Conclusion | ||
|
||
The integration between Cloudflare Zero Trust and SentinelOne provides organizations with a powerful tool for implementing Zero Trust security principles. By combining endpoint protection with access control, organizations can ensure that only secure and compliant devices can access sensitive resources. This approach significantly reduces the risk of compromised devices accessing corporate resources while maintaining user productivity through seamless authentication and authorization processes. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The integration between Cloudflare Zero Trust and SentinelOne provides organizations with a powerful tool for implementing Zero Trust security principles. By combining endpoint protection with access control, organizations can ensure that only secure and compliant devices can access sensitive resources. This approach significantly reduces the risk of compromised devices accessing corporate resources while maintaining user productivity through seamless authentication and authorization processes. | |
The integration between Cloudflare One and SentinelOne provides organizations with a powerful tool for implementing Zero Trust security principles. By combining endpoint protection with access control, organizations can ensure that only secure and compliant devices can access sensitive resources. This approach significantly reduces the risk of compromised devices accessing corporate resources while maintaining user productivity through seamless authentication and authorization processes. |
src/content/docs/reference-architecture/architectures/cloudflare-sase-with-sentinelone.mdx
Outdated
Show resolved
Hide resolved
…re-sase-with-sentinelone.mdx
Summary
New reference architecture for Cloudflare One and SentinelOne
Documentation checklist