Skip to content

Commit 3691e6b

Browse files
committed
Add more details
1 parent f1a3c40 commit 3691e6b

File tree

1 file changed

+3
-3
lines changed
  • src/content/docs/cloudflare-one/policies/gateway/tiered-policies

1 file changed

+3
-3
lines changed

src/content/docs/cloudflare-one/policies/gateway/tiered-policies/index.mdx

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,7 @@ In a tiered policy configuration, a top-level source account can share Gateway p
3030

3131
Gateway will automatically [generate a unique root CA](/cloudflare-one/connections/connect-devices/user-side-certificates/#generate-a-cloudflare-root-certificate) for each recipient account in an Organization. Each recipient account is subject to the default Zero Trust [account limits](/cloudflare-one/account-limits/).
3232

33-
Gateway evaluates source account policies before any recipient account policies. In a Cloudflare Organization, recipient accounts cannot bypass or modify source account policies. All traffic and corresponding policies, logs, and configurations for a recipient account will be contained to that recipient account. Organization owners can view logs for recipient accounts on a per-account basis, and [Logpush jobs](/logs/logpush/) must be configured separately.
33+
Gateway evaluates source account policies before any recipient account policies. In a Cloudflare Organization, recipient accounts cannot bypass or modify source account policies. All traffic and corresponding policies, logs, and configurations for a recipient account will be contained to that recipient account. Organization owners can view logs for recipient accounts on a per-account basis, and [Logpush jobs](/logs/logpush/) must be configured separately. When using DLP policies with [payload logging](/cloudflare-one/policies/data-loss-prevention/dlp-policies/logging-options/#log-the-payload-of-matched-rules), each recipient account must configure its own [encryption public key](/cloudflare-one/policies/data-loss-prevention/dlp-policies/logging-options/#set-a-dlp-payload-encryption-public-key).
3434

3535
```mermaid
3636
flowchart TD
@@ -78,7 +78,7 @@ flowchart TD
7878

7979
### Limitations
8080

81-
Tiered policies do not support [egress policies](/cloudflare-one/policies/gateway/egress-policies/). You cannot share policies with selectors that target [device posture checks](/cloudflare-one/identity/devices/), [Access private apps](/cloudflare-one/applications/non-http/self-hosted-private-app/), or [virtual networks](/cloudflare-one/connections/connect-networks/private-net/cloudflared/tunnel-virtual-networks/).
81+
Tiered policies do not support [egress policies](/cloudflare-one/policies/gateway/egress-policies/). Source accounts cannot share policies with selectors that target [device posture checks](/cloudflare-one/identity/devices/), [Access private apps](/cloudflare-one/applications/non-http/self-hosted-private-app/), or [virtual networks](/cloudflare-one/connections/connect-networks/private-net/cloudflared/tunnel-virtual-networks/). Source and recipient accounts can still create and apply policies with these selectors separately from the Organization share.
8282

8383
## Manage policies
8484

@@ -134,7 +134,7 @@ When you edit or delete a shared policy in a source account, Gateway will requir
134134

135135
## Manage settings
136136

137-
You can share Zero Trust settings from your source account to recipient accounts in your Cloudflare Organization, including the Gateway block page and extended email address matching.
137+
You can share Zero Trust settings from your source account to recipient accounts in your Cloudflare Organization, including the Gateway block page and extended email address matching. Other Gateway settings configured in a source account, such as [AV scanning](/cloudflare-one/policies/gateway/http-policies/antivirus-scanning/) and [file sandboxing](/cloudflare-one/policies/gateway/http-policies/file-sandboxing/), will not affect recipient account configurations.
138138

139139
{/* TODO: Turn these sections into a flexible partial or tabs. */}
140140

0 commit comments

Comments
 (0)