Skip to content

Commit 0e8d178

Browse files
authored
Update 2025-03-21-pdns-user-locations-role.mdx
Updated based on reviewers comments
1 parent 3f59fc1 commit 0e8d178

File tree

1 file changed

+9
-16
lines changed

1 file changed

+9
-16
lines changed
Lines changed: 9 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -1,28 +1,21 @@
11
---
2-
title: PDNS locations Management User Role
2+
title: Secure DNS Locations Management User Role
33
description: Create secure DNS locations using the new Cloudflare Zero Trust Locations Write role.
44
date: 2025-03-21T13:50:40Z
55
products: []
66
hidden: false
77
---
88

9-
We’re excited to introduce [Cloudflare Zero Trust Secure DNS Locations role](/cloudflare-one/connections/connect-devices/agentless/dns/locations/#secure-dns-locations), designed to give
10-
government customers granular control over third-party access while configuring their protective DNS (PDNS) solutions.
9+
We’re excited to introduce the [**Cloudflare Zero Trust Secure DNS Locations Write role**](/cloudflare-one/connections/connect-devices/agentless/dns/locations/#secure-dns-locations), designed to provide DNS filtering customers with granular control over third-party access when configuring their Protective DNS (PDNS) solutions.​
1110

12-
This new role enables IT administrators to grant external service partners targeted permissions for managing DNS locations, ensuring that highest security standards are upheld.
11+
Many DNS filtering customers rely on external service partners to manage their DNS location endpoints. This role allows you to grant access to external parties to administer DNS locations without overprovisioning their permissions.​
1312

14-
#### What makes a DNS location secure?
13+
**Secure DNS Location Requirements:**
1514

16-
- Mandatory [BYO IPv4/v6](/cloudflare-one/connections/connect-devices/agentless/dns/locations/dns-resolver-ips/#bring-your-own-dns-resolver-ip) usage if available on the account.
17-
- Source network filtering for IPv4/IPv6/DoT endpoints; token authentication OR source network filtering for the DoH endpoint.
18-
- All enabled location endpoints must comply with the above security policies.
19-
- Non-compliant edits (e.g., disabling authentication, using shared IPs when BYO IPv4/v6 is available) will be blocked and error messages displayed.
20-
- Users with this role must use their [Global API Key](/fundamentals/api/get-started/keys/); dedicated API tokens currently are unsupported.
15+
- Mandate usage of [Bring Your Own (BYO) IPv4/IPv6](https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/agentless/dns/locations/dns-resolver-ips/#bring-your-own-dns-resolver-ip) Resolver ranges if available on the account.
16+
17+
- Require source network filtering for IPv4/IPv6/DoT endpoints; token authentication or source network filtering for the DoH endpoint.​
18+
19+
You can assign the new role via Cloudflare Dashboard (`Manage Accounts > Members`) or via API. For more information, refer to the [Secure DNS Locations documentation](https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/agentless/dns/locations/#secure-dns-locations).
2120

22-
#### Notes for Admins
2321

24-
- **Role Assignment**:
25-
- Assign via Cloudflare Dashboard (`Member Management > All domains`) or API.
26-
- Requires `Cloudflare Secure DNS Locations Write Role` to view all DNS locations but only create/edit secure ones.
27-
- Users need `Cloudflare Zero Trust Read Only` role to access the dashboard.
28-
- **Avoid Conflicts**: Do not combine this role with [other roles](/cloudflare-one/roles-permissions/#footnote-label) containing broader permissions (e.g., `Administrator`,`Super Administrator`,`Cloudflare Zero Trust Write` and `Cloudflare Gateway`) to maintain security constraints.

0 commit comments

Comments
 (0)