Access, Cloudflare One - New strict service token authentication setting for Access
The strict service token authentication setting applies consistent behavior to requests made with service tokens. When the setting is on for a Zero Trust organization, Access handles requests with service token headers as follows: If authentication or authorization fails, Access always returns 401 or 403 instead of redirecting the client to the login page with 302. Only Service Auth policies can a…