Datawiza

MFA for on-prem apps

Add MFA to On-Prem Apps Without Code Changes

Protect on-prem web apps with Datawiza built-in MFA or MFA from your existing identity provider. Deploy in your data center, private cloud, customer cloud, or as a hosted service without rewriting login or moving the application.

See How It Works
Abstract access proxy gateway enforcing MFA in front of on-premises applications and private infrastructure

Why on-prem MFA is hard

Why MFA is difficult for on-prem apps

Many on-prem web applications were built before modern MFA, SAML, and OIDC. Rewriting login can create more risk than it removes, but security and compliance deadlines still apply.

The app must stay on premises

Residency, compliance, architecture, or operational constraints may keep the application and its data in your environment.

Login code is hard to change

Older frameworks, packaged applications, and fragile session behavior make authentication changes slow and risky.

The network path is complex

The app may already sit behind a VPN, ZTNA service, load balancer, gateway, reverse proxy, or internal DNS.

MFA requirements cannot wait

Security teams, auditors, insurers, and customers may require MFA before application modernization is ready.

Architecture

MFA at the Access Layer, Not Inside the App

Datawiza Access Proxy sits between users and the on-prem web app. Choose the MFA path that fits each application and user population.

Built-in MFA

Users sign in with their existing application credentials first. Datawiza then enforces MFA before access continues, with no separate IdP account or user synchronization required.

Existing IdP MFA

Connect Microsoft Entra ID, Okta, Ping, Cisco Duo, or another enterprise IdP over SAML or OIDC for SSO, MFA, and centralized identity policy.

In both modes, only approved traffic reaches the app. Application code, login flow, sessions, and user store stay unchanged.

App stays unchangedBuilt-in or IdP MFACentral policy and audit
MFA for on-prem apps architecture with Datawiza Access Proxy using built-in MFA or an existing identity provider
MFA for on-prem apps architecture with Datawiza Access Proxy using built-in MFA or an existing identity provider

How it works

Add MFA to on-prem apps in four steps

Put Access Proxy in the request path

Deploy Datawiza in your data center, private cloud, customer cloud, or hosted model and route web traffic through it.

Keep existing login or connect your IdP

Use built-in MFA with the application's current credentials, or integrate your existing IdP over SAML or OIDC.

Apply MFA and access policy

Enforce MFA, application-path rules, and centralized policy before users receive access to protected resources.

Forward approved requests

Datawiza sends approved traffic to the application while its code, login flow, user store, and deployment remain intact.

On-Prem MFA Demo

See How Datawiza Adds MFA to an On-Prem App

Watch Datawiza Access Proxy enforce MFA before access to an existing on-prem web app while its code, login flow, sessions, and user store remain unchanged. Use Datawiza built-in MFA or your existing enterprise IdP in a data center, private cloud, or hybrid environment.

App stays unchangedBuilt-in or IdP MFAData center, cloud, or hybrid
Add MFA to an existing on-prem application without code changes

Best fit

On-prem apps that are good candidates for MFA

This pattern is strongest when a web application must remain in its current environment but needs modern authentication now.

For a Microsoft-specific deployment pattern, see Azure MFA for on-premises applications.

Common candidates

Legacy and packaged web apps used by employees and contractors

Customer, partner, supplier, and vendor portals hosted on premises

ERP, HR, finance, administrative, and operational web applications

Apps behind F5, Nginx, Azure Application Gateway, AWS ALB, VPN, or ZTNA

Hybrid environments using Entra ID, Okta, Ping, Cisco Duo, or Datawiza built-in MFA

Deployment options

Deploy where the on-prem app runs

Keep the application local while choosing the access-layer deployment that matches your network, ownership, and operational model.

Data center

Run Datawiza close to applications and data that must remain in your own network.

Private cloud or VPC

Protect private apps in hybrid environments or staged cloud-migration architectures.

Existing gateway path

Fit Datawiza into the load balancer, reverse proxy, or gateway path already serving the app.

Datawiza-hosted service

Use a hosted service when it fits the application's routing and network requirements, with no application code changes.

FAQ

MFA for On-Prem Apps FAQ

What is MFA for on-prem apps?

MFA for on-prem apps adds a second authentication factor before users receive access to a web application hosted in a data center, private cloud, or other customer-managed environment. Datawiza enforces that control at the access layer so the application can stay where it runs today.

Can we add MFA without changing application code?

Yes. Datawiza Access Proxy sits in front of the on-prem web application and enforces MFA in the request path. The application does not need new MFA code, an SDK, or a rewritten login flow.

Do we need an identity provider?

No. Datawiza built-in MFA works with the application's existing credentials, so a new identity provider or user migration is not required. If you already use an enterprise IdP, Datawiza can integrate with it instead.

Can we use our existing identity provider for MFA?

Yes. Datawiza can integrate with identity providers such as Microsoft Entra ID, Okta, Ping, Cisco Duo, and others using SAML or OIDC, depending on the deployment.

Can Datawiza run in our data center or private cloud?

Yes. Datawiza supports customer-managed deployment in a data center, private cloud, or customer cloud. A hosted service is also available when it fits the application's network path.

Is this only for internal applications?

No. The same access-proxy pattern can protect internal apps and on-prem customer, partner, supplier, or vendor portals, provided they are web applications that can be placed behind the proxy.

Datawiza is Easy to Get Started

Sign up to secure your AI agents and critical enterprise apps

Try Datawiza