Part of Hideez Workforce Identity

Hideez AuthShield: Passwordless MFA & SSO for Legacy Applications

Bring secure SSO for legacy applications and passwordless MFA to on-premises web apps that modern IAM platforms cannot reach. Hideez AuthShield works as a secure access gateway, helping businesses modernize authentication without rebuilding or replacing critical applications.

Hideez AuthShield illustration
Why Legacy Applications Need Modern MFA and SSO
The problem

Why Legacy Applications Need Modern MFA and SSO

Many business-critical applications were developed before current identity and authentication standards became widely available. As a result, they may not connect to modern IAM platforms or support SSO, MFA, or passwordless access without extensive development.

  • Legacy apps cannot connect directly to modern IAM or SSO
  • Adding passwordless MFA may require significant development
  • Replacing a critical application may be costly or impractical
  • Manual passwords remain vulnerable to phishing and credential theft
The solution

What Is Hideez AuthShield?

Hideez AuthShield is an authenticating reverse proxy and an authentication solution for legacy applications that cannot natively connect to modern identity infrastructure. It functions as a secure access gateway, bringing MFA for legacy applications, passwordless authentication, and single sign-on to compatible web systems through Hideez Enterprise Server.

Users verify their identity through Hideez before reaching the protected application. The application credentials are stored on Hideez Enterprise Server and submitted server-side, so employees do not need to view, copy, or enter them in the browser.

What Is Hideez AuthShield?
How it works

A Secure Access Gateway Between Your Users and Applications

A Secure Access Gateway Between Your Users and Applications architecture diagram
1

Intercept

AuthShield receives the user’s sign-in request before it reaches the protected legacy application.

2

Authenticate

The user is verified through Hideez Enterprise Server using passwordless, phishing-resistant MFA over OpenID Connect.

3

Retrieve

AuthShield securely retrieves the application credentials assigned to the user from Hideez Enterprise Server.

4

Sign in

The credentials are submitted to the protected application server-side without requiring the user to enter or copy them.

5

Redirect

Once the application session has been created, the user is redirected to the requested resource.

This process gives employees a modern authentication experience while allowing the existing application to continue using its original sign-in mechanism.

Works with your identity stack

AuthShield complements the identity and access tools your organization already uses. It connects compatible legacy applications to the Hideez platform while allowing businesses to retain their existing directories, identity providers, and authentication policies. The exact integration depends on the identity environment, application architecture, and deployment requirements. Compatibility is evaluated before implementation.

Capabilities

Modern Authentication for Legacy Apps Without a Rebuild

Passwordless MFA for Legacy Apps

Passwordless MFA for Legacy Apps

Add phishing-resistant MFA for legacy apps that do not support modern authentication standards. Users complete an approved passwordless verification method instead of entering an application password or one-time code.

Credentials Secured on HES

Credentials Secured on HES

Application credentials are stored centrally and supplied server-side when access is approved. They are not displayed to users or entered through the browser, reducing exposure to phishing, accidental sharing, and browser-based credential capture.

OIDC-Based Authentication

OIDC-Based Authentication

AuthShield uses OpenID Connect to communicate with Hideez Enterprise Server. This standards-based approach allows the solution to work alongside supported identity providers and existing access infrastructure.

Nginx / Microsoft  IIS Reverse Proxy

Nginx / Microsoft IIS Reverse Proxy

AuthShield can be deployed as a hardened front-end layer running under Nginx or Microsoft IIS. It is typically placed in the organization’s DMZ, separating external access from the protected back-end application.

Support for Multiple Applications

Support for Multiple Applications

Each protected application uses its own AuthShield instance. Multiple instances can run on the same host using separate ports, allowing an organization to extend protection to several compatible legacy systems.

Adapted to Your Application

Adapted to Your Application

The Hideez team configures AuthShield for the authentication flow of the target application. This enables businesses to modernize access without undertaking a full application rebuild, subject to technical compatibility.

How it compares

Access With and Without Hideez AuthShield

Without AuthShield With AuthShield
Sign-in Password + one-time code Passwordless, phishing-resistant MFA
Credential exposure Credentials entered through the browser Credentials stored on Hideez Enterprise Server and submitted server-side
Application changes Custom development, rebuild, or replacement may be required Existing application generally remains unchanged
Central identity & MFA Often unavailable Managed through the Hideez platform
User experience Separate login for each application Simplified authentication and SSO
Implementation May require a long development project Proxy configured for the target application
Use cases

Where Teams Deploy AuthShield

Legacy and In-House Web Applications

Legacy and In-House Web Applications

Protect custom or vendor-provided applications that cannot directly integrate with current IAM platforms and are not practical to rebuild.

On-Premises Internal Portals

On-Premises Internal Portals

Add stronger authentication to intranet, back-office, and operational web applications that remain inside the organization’s infrastructure.

During an IAM Migration

During an IAM Migration

Keep legacy systems protected and available while modern applications and users are gradually moved to a new identity platform.

Regulated or Restricted Environments

Regulated or Restricted Environments

Keep application credentials on Hideez Enterprise Server and apply centralized authentication policies in environments with specific security, audit, or data-control requirements.

Part of the Hideez Workforce Identity Platform

AuthShield is one component of the Hideez Workforce Identity platform. It works with other Hideez products to provide centralized authentication and access management across business applications and workstations.

Hideez Server

Hideez Server is the control center of the platform. IT teams can manage users, authenticators, application integrations, credentials, workstation policies, and audit records from one administrative console.

USE CASES

Provision and deprovision users, rotate credentials, and enforce policies across every connected app and workstation from one place.

See who signed in, where, and when, with exportable logs that support your compliance and security reviews.

Run as SaaS, private cloud, or on-premises to meet your data-residency and regulatory requirements.

LEARN MORE
Hideez Authenticator

Hideez Authenticator turns a compatible smartphone into a secure authentication tool. Employees can use it to verify access to Windows workstations and business applications without entering a reusable password.

USE CASES

Unlock Windows PCs with a phone tap instead of a typed password.

The workstation locks automatically when the paired phone moves out of range.

Fast, personal sign-in on shared workstations in healthcare, manufacturing, and retail.

LEARN MORE
Passkeys

Passkeys provide phishing-resistant authentication based on FIDO2 and WebAuthn. Instead of submitting a shared secret, the user verifies access with a cryptographic credential protected by a device PIN, biometric check, or compatible security key.

USE CASES

Public-key credentials can't be reused or captured by fake sign-in pages.

Users sign in with the fingerprint or face unlock already on their device.

Built on FIDO2 / WebAuthn, so it works with modern browsers and identity providers.

LEARN MORE
Hideez Keys

Hideez Key devices combine FIDO2 authentication with USB, NFC, Bluetooth, and RFID capabilities. They are suitable for environments where employees cannot or should not use smartphones.

USE CASES

A hardware key for secure areas where smartphones are restricted.

One credential for app login and RFID door entry.

Issue and revoke access without provisioning a full device.

LEARN MORE

Hideez Partner Program

Designed for VADs, system integrators, and managed service providers in IT security.

BECOME A PARTNER
No app rebuild required

Modernize Legacy Access Without Rebuilding Your Applications

AuthShield adds SSO, passwordless MFA, and server-side credential handling to compatible legacy web applications without replacing them. Protect critical apps, reduce password exposure, and manage authentication through Hideez Enterprise Server.

FAQ

FAQs

Do we have to modify our application?

No. AuthShield runs in front of your app as a reverse proxy — the application itself stays untouched. There is no code change or rebuild.

Which applications are supported?

Any legacy web application. AuthShield is intended for legacy and on-premises web applications that cannot natively integrate with modern IAM, SSO, or MFA. Because authentication flows differ, Hideez evaluates each application before confirming compatibility.

Where is AuthShield deployed?

AuthShield is deployed on a separate host, typically in the organization’s DMZ, and can run under Nginx or Microsoft IIS. The specific architecture depends on the protected application and the organization’s network requirements.This setup helps keep the back-end application off the public internet.

How are credentials protected?

Application credentials are stored on Hideez Enterprise Server and submitted to the application server-side. They are not displayed to the user or entered through the browser, which reduces exposure to phishing, copying, and browser-based credential capture.

Can it cover multiple applications?

Yes. One AuthShield instance is configured for each application, and multiple instances can run on the same host using separate ports. Each application must be assessed and configured individually.

How does AuthShield handle security and compliance?

AuthShield reduces credential exposure by centralizing authentication and keeping application credentials out of the user-facing login flow. OIDC-based authentication, audit records, and deployment within the organization’s controlled infrastructure can support broader security and compliance programs. Compliance ultimately depends on the organization’s complete technical and administrative controls.

How is AuthShield licensed?

AuthShield is an optional add-on to Hideez Workforce Identity. It is licensed per protected legacy web application and billed annually in addition to applicable Hideez user licenses. Contact Hideez for a quote based on your deployment.

How does AuthShield integrate with our existing identity provider?

AuthShield connects legacy applications to Hideez Enterprise Server, which works with supported identity directories and providers. Requirements depend on your identity environment and application architecture.

What authentication methods does AuthShield support?

AuthShield supports methods available through Hideez, including passkeys, FIDO2 security keys, and Hideez Authenticator. IT can apply authentication policies by user role and application.

Can AuthShield be used during an IAM migration?

Yes. AuthShield can protect compatible legacy apps while other services move to a new IAM platform, keeping critical applications available with stronger access controls during the transition.

More questions? Contact Sales
Get started

Bring modern authentication to the apps you can't replace

Extend passwordless SSO and MFA to compatible legacy web applications without undertaking a complete rebuild. Hideez can assess your application, identity environment, and deployment requirements to determine the appropriate implementation.