Engineer Builds Terraform-Managed Demo Proving Zero Trust Policies With Entra ID and Cloudflare
A developer has published a fully Terraform-managed demonstration project that tests real Zero Trust failure modes using Microsoft Entra ID and Cloudflare Access. The setup registers Entra with Cloudflare twice — once via OIDC and once via SAML — to compare how each protocol handles identity and group claims. Three demo users with varying group memberships validate include, require, and exclude policy logic, exposing edge cases that typical Zero Trust write-ups overlook. The origin server verifies JWT signatures against the team's JWKS, resolves group GUIDs into readable names, and labels whether each claim came from the OIDC identity endpoint or the SAML assertion. The project is intended as a learning demonstration rather than a production template, and its full code is publicly available on GitHub.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in