
Table of contents
Need to add multi-factor authentication (MFA) or two-factor authentication (2FA) to an existing SAP web application without starting a major SAP upgrade or customization project? Datawiza Access Proxy places the authentication and policy layer in front of SAP, so Web GUI, Fiori, Enterprise Portal, Web Dynpro, ITS, SRM, ESS, supplier portals, and custom ABAP web apps can receive modern MFA without putting the rollout on a long Basis or modernization timeline.
Datawiza supports two deployment modes. Use Datawiza built-in MFA when users should keep their existing SAP credentials and do not need identity provider accounts. Or connect Datawiza to Microsoft Entra ID, Okta, Ping, Cisco Duo, Google, OneLogin, Shibboleth, AD FS, or another SAML or OIDC identity provider and enforce that provider's SSO, MFA, and conditional-access policies in front of SAP.
Why teams use Datawiza for SAP MFA and 2FA
SAP environments rarely consist of one current Fiori system and one user population. A typical estate mixes modern and older web components, multiple SAP landscapes, customized login flows, and external users who may never belong in the corporate identity provider. Datawiza provides one access-layer pattern across that mixed web estate.
- No custom SAP connector, plug-in, or in-stack MFA module project.
- Deploy MFA independently of the SAP upgrade and release cycle.
- Built-in MFA for suppliers, customers, contractors, retirees, and other users outside the enterprise IdP.
- Enterprise IdP integration through SAML or OIDC for SSO, MFA, passkeys, and conditional access.
- Application- and path-level policy plus centralized authentication and audit logs.
- Customer-managed deployment in a cloud or data center, or a Datawiza-hosted service.
How Datawiza adds MFA to SAP web applications

Datawiza Access Proxy sits in the HTTP or HTTPS request path in front of the SAP web application. It detects the login flow, applies the selected authentication policy, and allows only approved sessions to reach SAP. Because Datawiza runs outside the SAP application stack, the MFA rollout is decoupled from SAP upgrades, custom development, and release schedules.
Option 1: Datawiza built-in MFA
Users first sign in with the SAP application credentials they already have. After SAP verifies the username and password, Datawiza presents the MFA or 2FA challenge and grants access only after successful verification. Users see one password prompt — SAP's existing login — followed by MFA. No separate IdP account, directory migration, or IdP-to-SAP user synchronization is required.
This mode is particularly useful for SAP supplier, partner, customer, contractor, and employee self-service portals whose users are not managed in the corporate identity provider.
Option 2: MFA through your existing identity provider
For users already managed by an enterprise identity provider, Datawiza federates the login through SAML or OIDC. Microsoft Entra ID, Okta, Ping, Cisco Duo, Google, OneLogin, Shibboleth, AD FS, or another supported provider can perform authentication and MFA, while Datawiza translates and enforces the access flow in front of SAP.
This extends enterprise SSO, two-factor authentication, conditional access, and passkeys to SAP web components that would otherwise require separate Basis integration work. It also lets one policy layer cover a mixed estate instead of treating every SAP URL as a new identity project.
A practical SAP MFA rollout
1. Choose one SAP web URL and user population, such as Web GUI, Fiori, Portal, SRM, ESS, Web Dynpro, ITS, or a custom ABAP application.
2. Route that URL through Datawiza Access Proxy using DNS, a load balancer, gateway, or reverse proxy configuration.
3. Select built-in MFA for existing SAP users or connect the enterprise IdP through SAML or OIDC.
4. Validate login, session, logout, and application-path policy with a pilot group, then repeat the pattern across additional SAP web applications.
Which SAP web applications can Datawiza protect?
The access-layer pattern applies to browser-accessible SAP applications, including:
- SAP Web GUI (SAP GUI for HTML) and ITS paths
- SAP Fiori Launchpad
- SAP Enterprise Portal
- SAP Web Dynpro, BSP, and custom ABAP web applications
- SAP SRM and supplier portals
- Employee self-service, customer, dealer, and partner portals connected to SAP
One important boundary: Datawiza Access Proxy protects SAP web applications that use HTTP or HTTPS. SAP GUI for Windows is a desktop-client problem handled through SNC and SAP Secure Login Service, not through a web proxy.
MFA for SAP suppliers, customers, and external users
SAP's self-service and portal surfaces often expose sensitive information to users who do not have corporate IdP accounts. Employee Self-Service (ESS) contains payroll, bank, and benefits data, while customer and SRM supplier portals expose orders, invoices, contracts, and operational workflows.
With Datawiza built-in MFA, these users keep their existing SAP portal username and password. SAP verifies the login first; Datawiza then enforces two-factor authentication before the protected session is released. Teams avoid creating and licensing IdP accounts for populations that were never intended to join the workforce directory.
Datawiza access-layer MFA compared with SAP integration projects
Native SAML on NetWeaver or Fiori can be a good fit for a current SAP web stack, internal users already managed in an IdP, and a Basis team prepared to configure and test every system and landscape. SAP IAS is similarly appropriate for SAP-cloud-centered environments.
Datawiza is the stronger fit when the SAP web estate is mixed, external users must keep existing credentials, older components are difficult to federate, a major upgrade or customization effort is impractical, or the MFA deadline is shorter than a full SAP identity project. The proxy remains a component that you deploy or consume as a hosted service, but its rollout is decoupled from SAP upgrade and patch cycles.
SAP MFA, 2FA, and compliance coverage
SAP applications frequently sit inside SOX ITGC, NIS2, TISAX, and cyber insurance assessments. Auditors care about coverage and evidence: which SAP entry points require MFA, which users are challenged, and which logs prove enforcement. Datawiza centralizes those policies and authentication events outside the application stack. See the MFA compliance requirements hub for a framework-by-framework view.
Frequently asked questions
Can Datawiza add MFA or 2FA without a major SAP upgrade or customization project?
Yes. Datawiza Access Proxy enforces authentication and MFA in the web request path before protected SAP content is released. It is deployed outside the SAP application stack, so teams can protect SAP Web GUI, Fiori, Portal, Web Dynpro, ITS, SRM, ESS, and custom web applications without making MFA dependent on a major SAP upgrade, custom connector, or lengthy Basis project.
Do SAP users need new identity provider accounts?
No. With Datawiza built-in MFA, users keep their existing SAP application credentials. SAP verifies the login, and Datawiza adds the second authentication factor before access. For workforce users already in an IdP, Datawiza can instead use that provider's SSO and MFA policies.
Can Datawiza use Microsoft Entra ID, Okta, Ping, or Cisco Duo for SAP MFA?
Yes. Datawiza integrates with enterprise identity providers through SAML or OIDC, including Microsoft Entra ID, Okta, Ping, Cisco Duo, Google, OneLogin, Shibboleth, AD FS, and others. The IdP performs authentication and MFA; Datawiza enforces the resulting access flow in front of SAP.
How do I add two-factor authentication to SAP Web GUI?
Route the SAP Web GUI or ITS URL through Datawiza Access Proxy, then choose built-in MFA or connect an existing IdP. The proxy enforces 2FA before approved traffic reaches the protected SAP URL, avoiding a separate Web GUI upgrade or custom authentication integration project.
Can MFA be different for SAP admin users and regular users?
Yes. Datawiza can apply authentication and access policy by application, user population, and protected path. Administrative users or sensitive SAP paths can receive stronger MFA requirements while other users retain the appropriate policy for their role.
Does Datawiza cover SAP GUI for Windows?
No. SAP GUI for Windows uses the desktop SAP stack, SNC, and SAP Secure Login Service. Datawiza Access Proxy is designed for browser-based SAP web applications using HTTP or HTTPS.
Add MFA to one SAP web application first
Start with one SAP web URL and one user population. Datawiza can demonstrate the login flow, built-in or IdP-based MFA, policy enforcement, and audit evidence before you extend the pattern across the rest of the SAP web estate.
Book a demo and bring the SAP URL, user population, and MFA or compliance requirement you need to address.
SAP and SAP product names are trademarks or registered trademarks of SAP SE or its affiliates. This page describes an independent Datawiza solution and is not affiliated with or endorsed by SAP.



