---
source_url: "https://www.datawiza.com/add-sso-to-legacy-apps-and-on-premises-apps-without-modifying-source-code"
title: Add SSO and MFA to Legacy Apps Without Code Changes
mirrored_at: 2026-08-12T01:03:23.860Z
host: www.datawiza.com
cited_in_42a: true
mirror_canonical: "https://index.42a.ai/www.datawiza.com/add-sso-to-legacy-apps-and-on-premises-apps-without-modifying-source-code"
---

> **Original source:** https://www.datawiza.com/add-sso-to-legacy-apps-and-on-premises-apps-without-modifying-source-code

Why teams choose this path

## Modern authentication for apps that cannot be rewritten quickly

### No application rewrite

Protect apps that do not support SAML, OIDC, OAuth, or modern MFA natively.

### Use your existing identity provider

Connect Microsoft Entra ID, Okta, Ping, Cognito, Duo, or another identity provider instead of building new login code.

### Works for on-prem and hybrid apps

Place the proxy where traffic already flows, including on-premises, private cloud, public cloud, or hybrid environments.

### Central policy and audit

Enforce access rules before users reach the app and capture authentication and policy events in one place.

How it works

## Use an access proxy instead of changing every application

### Place Datawiza in front of the app

Route browser traffic through Datawiza Access Proxy before it reaches the protected legacy or on-prem web application.

### Connect identity and MFA

Use your enterprise IdP, built-in MFA, or a supported MFA provider to challenge users before app access.

### Apply policy before access

Evaluate user, group, app path, and rollout rules before allowing traffic to continue.

### Pass approved traffic to the app

Forward only approved requests to the original app while preserving the app experience users already know.

Best fit

## Where no-code SSO and MFA works best

[Datawiza Access Proxy](https://www.datawiza.com/products/access-proxy) is a strong fit when the application is important, exposed, or audit-sensitive, but not easy to modify. Instead of waiting for an app rewrite, teams can put modern authentication in front of the existing app.

Common candidates include

Legacy employee portals, admin consoles, and internal tools

On-premises web applications that still use older authentication patterns

Customer, partner, supplier, or vendor portals that need stronger access controls

Custom Java, .NET, PHP, Oracle, PeopleSoft, SharePoint, OWA, or ERP web applications

Apps that need SSO, MFA, headers, policy, and audit without source-code changes

Deployment

## Roll out app by app, without a big-bang migration

### Start with one high-risk app

Pilot the access proxy with one legacy app, validate the user experience, then expand.

### Hosted or self-managed

Use Datawiza-hosted deployment or run the proxy in your own cloud, private cloud, or on-prem environment.

### Policy by group or path

Apply MFA and SSO rules by user group, app path, app type, or rollout phase.

### Rollback-friendly routing

Because the app itself is not rewritten, teams can plan DNS or routing changes with a clearer rollback path.

FAQ

## Legacy app SSO and MFA FAQ

Do we need to modify application source code?

No. The access proxy pattern lets Datawiza enforce SSO and MFA before traffic reaches the application, so teams avoid source-code changes for the protected app.

Does this work for on-premises applications?

Yes. Datawiza can be deployed in front of on-premises, cloud-hosted, private-cloud, or hybrid web applications when traffic can be routed through the proxy.

Can we use our existing identity provider?

Yes. Datawiza can work with common enterprise identity providers and MFA services, including Microsoft Entra ID, Okta, Ping, Amazon Cognito, and Duo.

Can we roll this out gradually?

Yes. Most teams start with one app, validate policy and user experience, then expand the same pattern to more legacy and on-prem applications.

## Ready to protect one legacy app first?

Bring one legacy or on-prem web application. Datawiza can show how SSO, MFA, policy, and audit fit in front of it without changing the app.