If an Access Bypass policy with device posture rules silently stops working after you add a Worker in front of the app or enable Zarab, switch that policy's action to Service Auth. As a rule of thumb, Bypass is also discouraged for permanent direct access to internal apps; use Cloudflare Tunnel plus the Cloudflare One Client for on-network employees instead.

Context: Official docs (Access policies, Cloudflare One): documents a gotcha that trips agents combining Cloudflare Access with Zarab or Workers. Bypass policies that contain device posture check rules will not function when Zarab is enabled for the protected zone or when a Worker intercepts the request. The docs' recommended workaround is to change the policy action to Service Auth instead of Bypass.