Cloudflare MFA Lockdown for ERP

Job ID: 40382678

Budget: ₹1,500 – ₹12,500 INR

My internal ERP sits behind a private domain that I’m ready to move under Cloudflare Zero Trust. The goal is simple: when someone tries to reach the ERP URL, the prompt must enforce multi-factor authentication and allow the session to open only if the request comes from one of our office computers on our Wi-Fi network. Anything originating elsewhere—home, café, mobile hotspot—should be denied outright.

Here is what I need from you as the security specialist familiar with Cloudflare Access, Gateway, and device posture rules:

• Configure the domain inside Cloudflare, enabling the security features that sit in front of the ERP server (Firewall, WAF, DDoS protection).
• Create an Access policy that ties identity (Google Workspace / Azure AD, or another SSO you recommend) to mandatory MFA. TOTP or push-based authenticators are both acceptable.
• Whitelist only the MAC-addressed office computers or, if you prefer a cleaner approach, use Cloudflare’s device client plus serial-number/device-certificate enforcement so that “Only office computers” truly means only those devices.
• Ensure the policy respects our Wi-Fi network range; requests originating from any other subnet must be blocked without even showing a login screen.
• Provide a short hand-off document (screenshots or screencast) covering the rules, how to onboard a new machine, and how to revoke access instantly if a laptop is lost.
• Run end-to-end tests with me—first inside the office, then from an outside network—to confirm the lockout and the MFA prompt both work as intended.

Success is measured when:
1. The ERP is accessible from the office Wi-Fi on approved computers after passing MFA.
2. A test request from an unapproved device or off-premises network fails automatically.
3. All settings are documented clearly enough that I can audit or adjust them later without guesswork.

If you have recent experience hardening internal apps with Cloudflare and MFA, let’s secure this right away.