No application rewrite
Protect apps that do not support SAML, OIDC, OAuth, or modern MFA natively.
No-code SSO and MFA
Put Datawiza Access Proxy in front of existing web apps to enforce SSO, MFA, app access policy, and audit without rewriting login, upgrading app servers, or migrating users first.

Why teams choose this path
Protect apps that do not support SAML, OIDC, OAuth, or modern MFA natively.
Connect Microsoft Entra ID, Okta, Ping, Cognito, Duo, or another identity provider instead of building new login code.
Place the proxy where traffic already flows, including on-premises, private cloud, public cloud, or hybrid environments.
Enforce access rules before users reach the app and capture authentication and policy events in one place.
How it works
Route browser traffic through Datawiza Access Proxy before it reaches the protected legacy or on-prem web application.
Use your enterprise IdP, built-in MFA, or a supported MFA provider to challenge users before app access.
Evaluate user, group, app path, and rollout rules before allowing traffic to continue.
Forward only approved requests to the original app while preserving the app experience users already know.
Best fit
Datawiza Access Proxy is a strong fit when the application is important, exposed, or audit-sensitive, but not easy to modify. Instead of waiting for an app rewrite, teams can put modern authentication in front of the existing app.
For a broader overview of the pattern, see no-code MFA and MFA for web applications.
Common candidates include
Legacy employee portals, admin consoles, and internal tools
On-premises web applications that still use older authentication patterns
Customer, partner, supplier, or vendor portals that need stronger access controls
Custom Java, .NET, PHP, Oracle, PeopleSoft, SharePoint, OWA, or ERP web applications
Apps that need SSO, MFA, headers, policy, and audit without source-code changes
Deployment
Pilot the access proxy with one legacy app, validate the user experience, then expand.
Use Datawiza-hosted deployment or run the proxy in your own cloud, private cloud, or on-prem environment.
Apply MFA and SSO rules by user group, app path, app type, or rollout phase.
Because the app itself is not rewritten, teams can plan DNS or routing changes with a clearer rollback path.
FAQ
No. The access proxy pattern lets Datawiza enforce SSO and MFA before traffic reaches the application, so teams avoid source-code changes for the protected app.
Yes. Datawiza can be deployed in front of on-premises, cloud-hosted, private-cloud, or hybrid web applications when traffic can be routed through the proxy.
Yes. Datawiza can work with common enterprise identity providers and MFA services, including Microsoft Entra ID, Okta, Ping, Amazon Cognito, and Duo.
Yes. Most teams start with one app, validate policy and user experience, then expand the same pattern to more legacy and on-prem applications.
Bring one legacy or on-prem web application. Datawiza can show how SSO, MFA, policy, and audit fit in front of it without changing the app.
Sign up to secure your AI agents and critical enterprise apps