You are currently viewing Matrix Server Cloudflare 2FA

Matrix Server Cloudflare 2FA

Securing the Matrix Server Cloudflare 2FA isn’t difficult, but it does require a bit of effort. Here’s the setup guide from cloudflare.com.

The real effort lies solely in setting up the Cloudflare tunnel through which the applications are routed. For me, almost everything now runs through Cloudflare. This not only ensures high reliability but also enhances security.

This post focuses exclusively on configuring Matrix/Element.

If you haven’t set up Cloudflare yet and would like to do so, simply follow this post. There you’ll find detailed step-by-step instructions.

Although this post isn’t exactly brand-new anymore, and Cloudflare’s user interface has changed a bit since then, it still does a good job of walking you through the setup process. I’ll update the post as soon as I find the time.

Matrix Server (Synapse) – Message Server

The message server is the actual heart of the system. All messages are exchanged, sent, and received through it. The web interface accesses this server directly.

While securing the server with 2FA would be possible using a service token or appropriate rules, this isn’t standard practice and can sometimes lead to access issues.

Element Server – Web Interface

The Element Server already features its own device management system as well as built-in end-to-end encryption and can generally be considered secure. However, there is still room for improvement in some areas. Work is already underway on relevant enhancements. You can follow the current development status on GitHub.

In the following video, I’ll show you how to further secure the Element Server with two-factor authentication—in this example, using email OTP and a passkey.

2FA Alternative

A third option is to set up your own Docker instance with a local 2FA system such as Authelia. We cover this option in detail in a separate video.

Video: Matrix Server Cloudflare 2FA

Language: 🇩🇪|🇬🇧
☝️ Use YouTube subtitles for all languages.

Cloudflare Zero Trust: How to Set Up Passkey Login Correctly for Your Own Websites

Anyone who wants to secure their website or WordPress login using Cloudflare Access often runs into a problem: Logging in with a fingerprint, Touch ID, or YubiKey (passkey) fails, or the system keeps asking for an email address.

Follow these three steps to set up Cloudflare Zero Trust correctly:

1. Eine Anwendung erstellen

In Cloudflare Zero Trust, go to Applications → New Application.

Select “Self-hosted and private,” and then click “Continue with ‘Self-hosted and private‘.”

Next, configure the application:

  • Subdomain: element
  • Domain: your domain, e.g., your-domain.com
  • Path: leave blank

Authentication (Identity)

  • Accept all identity providers: on
  • Leave all other settings unchanged.

Authentication (MFA)

  • Select “Adjust MFA Settings.”
  • MFA Method: Biometrics and Security Key
  • Authentication Duration: Custom
  • Enter 720 hours (1 month).

NeuCreate a guideline

Click “Create New Policy”.

  • Selector: Email
  • In the line below, enter all email addresses that should be granted access.
  • Policy Name: e.g., Element Passkey
  • Policy Session Duration: 1 month
  • Select “Customize MFA Settings.”
  • MFA Method: Biometrics and Security Key
  • Authentication Duration: Custom
  • 720 hours (1 month)

Then click Save and close the Policy dialog box.

Finally, click Save again and close the Add Application dialog box.

Enable the App Launcher (Prerequisite)

The App Launcher is your personal control center at Cloudflare. If it is disabled, you will receive an error message when you try to access it, and you will not be able to store passkeys.

  • Here’s how: In the Cloudflare Zero Trust Dashboard, click Access Control > Access Settings on the left.
  • Click “Manage” next to App Launcher on the right.
  • Selector: Email
  • In the line below, enter all email addresses that should be granted access.
  • Policy Name: e.g., Element Passkey
  • Policy Session Duration: 1 month
  • Select “Customize MFA Settings.”
  • MFA Method: Biometrics and security keys
  • Authentication Duration: Custom
  • 720 hours (1 month)

Enable Passkeys / Biometrics as MFA

For the system to accept passkeys as a form of authentication at all, they must be enabled centrally.

  • Here’s how: Go to Access Control > Access Settings and scroll down to the “MFA options” section. Make sure that “Biometrics and Security Keys” (Touch ID, Windows Hello, Face ID) is set to “Enabled.”

3. What You Absolutely Must Keep in Mind

  • One-time setup: Access your personal Cloudflare URL ([https://ihr-name.cloudflareaccess.com](https://ihr-name.cloudflareaccess.com)) Log in one last time using the email code, click on your profile/account in the top-right corner, and add your passkey under “MFA devices.”

In this example, I’ve set the session duration to one month everywhere. Cloudflare does not currently allow a longer session duration.

You can choose and customize the MFA options—such as an authenticator app, security key, passkey, or other methods—to suit your own needs.


Donate Bild

Support / Donation Link for the Channel
If my posts have been helpful or supported you in any way, I’d truly appreciate your support 🙏

PayPal Link
Bank transfer, Bitcoin and Lightning


#Cloudflare #ZeroTrust #Passkey #CyberSecurity #WebDesign

Leave a Reply