Publish On-Premises Apps with Microsoft Entra External ID and Datawiza

Table of contents
You can publish on-premises web applications for customers and partners using Microsoft Entra External ID in an external tenant and Datawiza Access Proxy. External ID authenticates users, while Datawiza sits in front of the application and enforces access. Datawiza's Entra External ID integration guide documents the identity connection.
This approach lets organizations keep ordering portals, service platforms, and custom business applications in their data centers while managing customer and partner identities separately from employees. They do not need to add every portal user as a B2B guest in their workforce tenant.
The key limitation is that Microsoft Entra Application Proxy is unavailable in external tenants, according to Microsoft's supported-feature matrix. Datawiza provides an application access layer that integrates with this external-tenant identity model.
Why use an external tenant for customers and partners?
Microsoft Entra External ID covers two distinct identity models:
- B2B collaboration in a workforce tenant: external users collaborate with employees and access organizational resources as guests.
- Customer identity in an external tenant: consumers and business customers access applications through a separate directory, with its own app registrations and sign-up and sign-in flows.
Microsoft describes these as distinct tenant configurations. Users still have accounts in the external directory; the difference is where those identities are managed.
For an organization operating a customer or partner portal, that separation can support a clearer operating model. The portal team can manage customer onboarding, application access, and account lifecycles without adding the entire portal population to the employee directory.
B2B guests remain appropriate for many collaboration scenarios. The reason to choose an external tenant is the application's audience and identity requirements, rather than guest count alone.
Does Entra Application Proxy support external tenants?
Microsoft Entra Application Proxy does not support external tenants. Microsoft's enterprise application feature comparison lists it as unavailable for this tenant configuration.
Application Proxy can support B2B guest access through a workforce tenant, as Microsoft documents in its guide to on-premises access for B2B users. That serves a different identity model from using a dedicated external tenant for the portal's customers and partners.
When an organization has chosen the external-tenant model, it needs an application access layer that can integrate with that tenant. Datawiza Access Proxy provides that connection.
How Datawiza Access Proxy connects External ID to on-premises apps
Datawiza Access Proxy runs as a reverse proxy in front of the web application, with network access to its backend. It connects to the external tenant using OpenID Connect (OIDC). Entra External ID handles user authentication; Datawiza controls the application access path.
The request flow is:
- A customer or partner opens the portal's public HTTPS address.
- Datawiza redirects the browser to the configured Entra External ID external tenant.
- The user completes the configured sign-in flow and any required authentication challenges.
- Datawiza validates the authentication response, establishes its session, and applies access policy.
- Approved traffic reaches the on-premises application through the configured backend integration.

The application can stay in the data center. The organization provides a reachable HTTPS entry point to Datawiza and a protected route from Datawiza to the backend. The backend must accept traffic only through the trusted proxy path, so users cannot bypass authentication. This follows Datawiza's documented deployment architecture.
How to deploy Datawiza with Entra External ID
Start with one representative application and a small test group.
- Prepare the external tenant. Configure the customer sign-in experience and register the web application that Datawiza will integrate with. Use the single-tenant account type required by Microsoft: accounts in that organizational directory only. Associate the application with the appropriate user flow.
- Configure the identity connection. Set the application client ID, client secret, and correct external-tenant issuer in Datawiza. Register the exact production HTTPS callback URL used by the proxy. Follow the Datawiza External ID guide for the connection values, alongside Microsoft's current registration requirements.
- Deploy the proxy and configure routing. Set the public application address, TLS, and backend destination. Give the proxy the connectivity it needs to the application, identity provider, and management services. See Datawiza deployment prerequisites.
- Map identities and define access. Configure the attributes the backend requires and allow access only to the intended users and application paths. Datawiza supports access rules based on available identity attributes and request properties.
- Validate the complete journey. Test sign-in, denied access, account mapping, logout, session expiry, and backend isolation. Confirm that one customer or partner cannot access another organization's records.
Can partners sign in with existing Microsoft Entra accounts?
Partners with organizational Microsoft Entra accounts can use those credentials when their home tenant is configured as an OIDC identity provider in the external tenant. Microsoft's Entra tenant federation guide explains this configuration, including the creation of a user account in the external tenant. It does not require inviting the user into your workforce tenant for this portal access path.
Federation must be configured for the intended identity providers; it does not automatically enable every partner tenant. Authentication and MFA behavior should be tested across the complete journey.
Publish your on-premises apps with Datawiza
Organizations should be able to choose an identity model that fits their customers and partners while continuing to use valuable on-premises applications.
Datawiza Access Proxy makes that possible by connecting Entra External ID authentication to a controlled application access path. Customer identities can stay in the external tenant, employee identities can stay in the workforce tenant, and supported web applications can remain where they run today.
Explore Datawiza Access Proxy or schedule a demo to review your application, identity mapping, and deployment requirements.



