How do I deploy WARP to my team?
Cloudflare WARP must be installed on each device that needs AI tool blocking. There are three deployment options: **Option A — Self-serve (small teams)** Send your team a link to one.one.one.one to download WARP. After installing, they open Settings → Account → Login to Cloudflare Zero Trust → enter your team name → authenticate with their company email. **Option B — MDM push (managed devices)** For Intune, JAMF, or Google Admin Console: create a WARP deployment profile with your Zero Trust org settings pre-configured. WARP installs silently and auto-enrolls. See: developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/deployment/mdm-deployment/ **Option C — Office network DNS (no install)** Set your office router's DNS to your Cloudflare Gateway IP. Every device on the WiFi gets protected. No installs needed. But remote workers aren't covered. **Before deploying**, make sure you've set up an enrollment policy in Cloudflare Zero Trust: Settings → WARP Client → Device enrollment → Add a rule that allows your company's email domain.