Skip to content

Commit ec50607

Browse files
AdamBouhmadkodster28dcpena
authored andcommitted
user-groups and permission policies beta changelog entry (cloudflare#22755)
* user-groups and permission policies beta changelog entry * Update deprecation notice in the Changelog * Update 2025-06-02-user-groups-beta.mdx * copy edits based on feedback * Corrections * Apply suggestions from code review * Update src/content/changelog/fundamentals/2025-06-02-user-groups-beta.mdx --------- Co-authored-by: kodster28 <[email protected]> Co-authored-by: Denise Pena <[email protected]> Co-authored-by: Kody Jackson <[email protected]>
1 parent 011e748 commit ec50607

File tree

2 files changed

+34
-0
lines changed

2 files changed

+34
-0
lines changed
444 KB
Loading
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
---
2+
title: Cloudflare User Groups & Enhanced Permission Policies are now in Beta
3+
description: Simplifying the management of users, groups, and permissions within Cloudflare.
4+
products:
5+
- fundamentals
6+
date: 2025-06-02
7+
---
8+
9+
We're excited to announce the Public Beta launch of **User Groups for Cloudflare Dashboard** and **System for Cross Domain Identity Management (SCIM) User Groups**, expanding our RBAC capabilities to simplify user and group management at scale.
10+
11+
We've also visually overhauled the **Permission Policies UI** to make defining permissions more intuitive.
12+
13+
**What's New**
14+
15+
**User Groups [BETA]**: [User Groups](/fundamentals/manage-members/user-groups/) are a new Cloudflare IAM primitive that enable administrators to create collections of account members that are treated equally from an access control perspective. User Groups can be assigned permission policies, with individual members in the group inheriting all permissions granted to the User Group. User Groups can be created manually, via our APIs, or Terraform.
16+
17+
**SCIM User Groups [BETA]**: Centralize & simplify your user and group management at scale by syncing memberships directly from your upstream identity provider (like Okta or Entra ID) to the Cloudflare Platform. This ensures Cloudflare stays in sync with your identity provider, letting you apply Permission Policies to those synced groups directly within the Cloudflare Dashboard.
18+
19+
:::note
20+
SCIM Virtual Groups (identified by the pattern `CF-<accountID>-<Role Name>` in your IdP) are deprecated as of 06/02/25. We recommend migrating SCIM Virtual Groups implementations to use [SCIM User Groups](/fundamentals/account/account-security/scim-setup/). If you did not use Virtual Groups, no action is needed.
21+
:::
22+
23+
**Revamped Permission Policies UI [BETA]**: As Cloudflare's services have grown, so has the need for precise, role-based access control. We've given the Permission Policies builder a visual overhaul to make it much easier for administrators to find and define the exact permissions they want for specific principals.
24+
25+
![Updated Permissions Policy UX](~/assets/images/changelog/fundamentals/2025-06-02-permissions-policy-ux.png)
26+
27+
:::note
28+
When opting into the Beta for User Groups and Permission Policies, you'll be transitioning to a new experience. Please be aware that opting out isn't currently available.
29+
:::
30+
31+
For more info:
32+
33+
- [Get started with User Groups](/fundamentals/manage-members/user-groups/)
34+
- [Explore our SCIM integration guide](/fundamentals/account/account-security/scim-setup/)

0 commit comments

Comments
 (0)