To provide more granular controls, we refined the existing roles for Email Security and launched a new Email Security role as well.
All Email Security roles no longer have read or write access to any of the other Zero Trust products:
- Email Configuration Admin
- Email Integration Admin
- Email Security Read Only
- Email Security Analyst
- Email Security Policy Admin
- Email Security Reporting
To configure Data Loss Prevention (DLP) or Remote Browser Isolation (RBI), you now need to be an admin for the Zero Trust dashboard with the Cloudflare Zero Trust role.
Also through customer feedback, we have created a new additive role to allow Email Security Analyst to create, edit, and delete Email Security policies, without needing to provide access via the Email Configuration Admin role. This role is called Email Security Policy Admin, which can read all settings, but has write access to allow policies, trusted domains, and blocked senders.
This feature is available across these Email Security packages:
- Advantage
- Enterprise
- Enterprise + PhishGuard
Source: Cloudflare

![Power Pages - Security scan recommendations in Security Hub [MC1184033] 2 pexels shkrabaanthony 5243990](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-shkrabaanthony-5243990-150x150.webp)


![(Updated) New Tools feature coming to the Microsoft Copilot Chat prompt box [MC1122153] 5 pexels federico orlandi 1423142 3260626.bak](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-federico-orlandi-1423142-3260626.bak_-150x150.webp)
