No modern protocol support
Older apps may not support SAML, OIDC, OAuth, or direct Microsoft Entra integration.
Microsoft Entra MFA for on-prem apps
Use Datawiza Access Proxy with Microsoft Entra ID to enforce SSO, MFA, Conditional Access, and audit for legacy and on-prem web applications that cannot be changed quickly.

Why it matters
Older apps may not support SAML, OIDC, OAuth, or direct Microsoft Entra integration.
Changing login code in critical on-prem apps can require testing, downtime planning, and release coordination.
Apps may run in datacenters, private networks, or mixed cloud/on-prem environments.
Security teams need a clear record of who accessed which app and which policy was enforced.
How it works
Route users through the proxy before requests reach the on-premises application.
Use Entra ID as the identity provider for SSO, MFA, Conditional Access, and group-based policy.
Require MFA or step-up authentication before users reach the protected application.
Send only approved traffic to the app while Datawiza handles identity enforcement at the access layer.
Best fit
This approach is useful when you want Microsoft Entra ID and Azure MFA controls in front of apps that were not built for direct Entra integration. It is especially helpful for on-premises web apps, internal portals, admin apps, and legacy systems that cannot be rewritten quickly.
For related guidance, see no-code MFA and Datawiza Access Proxy.
Common scenarios include
Protecting on-prem web apps with Entra ID SSO and MFA
Extending Conditional Access-style enforcement to older apps
Adding MFA to internal tools without changing app source code
Using a phased rollout before a larger app modernization project
Deployment
Run Datawiza near applications that remain in your datacenter or private network.
Deploy in Azure, AWS, GCP, or your private cloud depending on network and security needs.
Use a hosted approach when faster rollout and lower operational overhead matter most.
Protect different apps with different deployment models while keeping policy consistent.
FAQ
Yes, when the application traffic is routed through an enforcement layer such as Datawiza Access Proxy. Datawiza connects to Microsoft Entra ID and enforces authentication before app access.
No. Datawiza sits in front of the app, so the app does not need to support modern identity protocols directly.
Datawiza can use Microsoft Entra ID as the identity provider, allowing organizations to align app access with their broader Entra ID policy model.
No. The same access-layer pattern can protect internal apps, admin portals, partner portals, and other browser-based applications when routed through Datawiza.
Start with one application that cannot be rewritten quickly. Datawiza can show how Entra ID, MFA, and proxy-based access control fit in front of it.
FAQ
Yes. Datawiza Access Proxy can extend Microsoft Entra ID MFA and Conditional Access to on-premises web apps by sitting in front of the application and enforcing the identity policy before access is allowed.
Not always. Microsoft options can be a good fit for certain Microsoft-centered access patterns, but Datawiza is often the faster path for legacy, homegrown, and vendor web apps that need MFA without application changes. See /blog/industry/an-alternative-to-entra-app-proxy for a deeper comparison.
Datawiza can protect the app at the access layer. You keep the existing application code and use Datawiza to handle SSO, MFA, session policy, headers, and audit in front of the app.
Sign up to secure your AI agents and critical enterprise apps