Avoid a full app rewrite
Add customer login and MFA at the access layer instead of rebuilding every legacy application.
Customer identity for existing apps
Use Datawiza Access Proxy to extend Azure AD B2C, now part of the Microsoft Entra External ID family, to customer-facing, partner, legacy, and on-prem web applications without rebuilding login.

Why teams use this pattern
Add customer login and MFA at the access layer instead of rebuilding every legacy application.
Keep the application, session model, and backend logic intact while modernizing access.
Add stronger authentication for customers, partners, members, vendors, or other external users.
Pilot one portal or app first, then expand the same pattern across more web properties.
How it works
Users reach the application through Datawiza Access Proxy before they reach the legacy app.
Use Azure AD B2C or Entra External ID as the customer identity provider.
Challenge users and apply access rules before allowing traffic to continue.
Datawiza can pass approved identity context to the app through supported proxy patterns.
Best fit
This page is most relevant when the goal is customer or external-user access for an application that already exists. If the app cannot be changed quickly, Datawiza lets teams place a modern identity layer in front of it.
For adjacent use cases, see MFA for customer portals and no-code MFA.
Good candidates include
Customer portals and partner portals
Member, patient, student, vendor, or supplier portals
On-premises web apps that need external-user login and MFA
Legacy apps that are not ready for a full CIAM or login migration
Deployment
Choose a Datawiza-hosted deployment or run the proxy in your own environment.
Start with one customer-facing app and expand after validating user experience and policy.
Use identity and MFA policies that fit the audience rather than forcing every app into the same model immediately.
Capture authentication and policy events for security review and operations.
FAQ
Many teams still use the Azure AD B2C name in existing projects and searches. Microsoft has also introduced the Microsoft Entra External ID family for customer and external identity scenarios.
In many browser-based scenarios, yes. Datawiza can sit in front of the app and enforce login and MFA before traffic reaches the application.
No. The pattern can support on-premises, private cloud, public cloud, and hybrid applications when the traffic can be routed through Datawiza.
Yes. It is a strong fit for existing customer, partner, member, and vendor portals that need stronger authentication without a full rewrite.
Use Datawiza to test Azure AD B2C or Entra External ID login in front of one portal before expanding across more legacy apps.
Sign up to secure your AI agents and critical enterprise apps