Part of Hideez Workforce Identity

Hideez AuthShield: Passwordless MFA & SSO for Legacy Apps

Give users passwordless, phishing-resistant MFA and single sign-on on the legacy and on-premises web apps modern IAM can't reach — through a secure access gateway, with no code changes.

Hideez AuthShield: Passwordless MFA & SSO for Legacy Apps
Your legacy apps weren't built for modern security
The problem

Your legacy apps weren't built for modern security

Most business-critical apps were built before modern identity standards existed, so securing legacy authentication usually means a costly rebuild — or living with password risk.

  • Can't connect to modern IAM or SSO
  • Adding passwordless MFA usually means a rebuild
  • Replacing the app isn't realistic
  • Manual passwords keep the door open to phishing
What it is

What Is Hideez AuthShield?

Hideez AuthShield is an authenticating reverse proxy — a secure access gateway that brings passwordless MFA and SSO to legacy web applications, connecting them to Hideez Enterprise Server (HES).

It gives users passwordless, phishing-resistant MFA and single sign-on to applications that were never built for modern identity, without rebuilding or replacing them. The app's credentials stay on HES and are supplied server-side, so they never reach the user's browser.

What Is Hideez AuthShield?
How it works

A secure access gateway between your users and your app

A secure access gateway between your users and your app architecture diagram
1

Intercept

AuthShield catches the user's sign-in request before it reaches the legacy app.

2

Authenticate

The user is verified on Hideez Enterprise Server with passwordless, phishing-resistant MFA (over OIDC).

3

Retrieve

AuthShield pulls the app's stored credentials securely from HES, server-side.

4

Sign in

It submits the app's stored credentials for the user, server-side.

5

Redirect

The application session is created and the user is seamlessly redirected in.

Works with your identity stack
Capabilities

Modern authentication for legacy apps — without a rebuild

Passwordless MFA for legacy apps

Phishing-resistant, passwordless sign-in on apps that never supported it — no password to type, and nothing for attackers to phish.

Credentials secured on HES

Stored server-side and supplied for the user — they never reach the browser, so browser malware can't steal them.

OIDC-standard authentication

Built on OpenID Connect — standards-based, so it fits alongside the identity tools you already run.

Nginx / Microsoft IIS reverse proxy

Deploys as a hardened front-end layer inside your DMZ — no exposure of the back-end app.

Multi-app ready

Run one AuthShield instance per application, with many instances on a single host.

Adapted by Hideez

Our team tailors AuthShield to your specific legacy application, fast.

How it compares

With vs without AuthShield

Without AuthShield With AuthShield
Sign-in Password + one-time code Passwordless MFA (phishing-resistant)
Credential exposure Typed in the browser (phishable) Stored on HES, never in the browser
Changes to your app Rebuild or replace None — app untouched
Central identity & MFA
Time to value Months (rebuild) Fast (proxy adaptation)
Use cases

Where teams deploy AuthShield

Legacy & in-house web apps

Custom or vendor applications that can't integrate with modern IAM and won't be rebuilt.

On-premises internal portals

Intranet and back-office web apps you keep off the public internet.

During an IAM migration

Protect and keep legacy apps running while you roll out modern identity.

Regulated / restricted environments

Credentials stay on your Hideez Enterprise Server — never in the browser or a third-party cloud.

Part of the Hideez Workforce Identity platform

AuthShield is one part of the Hideez Workforce Identity platform. Explore the products that work together to make your workforce passwordless.

Hideez Server

The control center of the platform — manage users, credentials, app integrations, workstation policies, and a full audit trail from one console, deployed as SaaS, private cloud, or on-premises.

USE CASES

Provision and deprovision users, rotate credentials, and enforce policies across every connected app and workstation from one place.

See who signed in, where, and when, with exportable logs that support your compliance and security reviews.

Run as SaaS, private cloud, or on-premises to meet your data-residency and regulatory requirements.

LEARN MORE
Hideez Authenticator

Turns a smartphone into a secure identity key: employees sign in to Windows workstations and business apps with a tap, and proximity can lock the PC when they step away.

USE CASES

Unlock Windows PCs with a phone tap instead of a typed password.

The workstation locks automatically when the paired phone moves out of range.

Fast, personal sign-in on shared workstations in healthcare, manufacturing, and retail.

LEARN MORE
Passkeys

Phishing-resistant FIDO2 / WebAuthn sign-in using device biometrics or a security key — no shared secret to steal, built on open standards that work across modern browsers.

USE CASES

Public-key credentials can't be reused or captured by fake sign-in pages.

Users sign in with the fingerprint or face unlock already on their device.

Built on FIDO2 / WebAuthn, so it works with modern browsers and identity providers.

LEARN MORE
Hideez Keys

Compact hardware security keys combining Bluetooth, NFC, RFID and USB in one device — passwordless access to apps and physical doors, ideal where phones aren't allowed.

USE CASES

A hardware key for secure areas where smartphones are restricted.

One credential for app login and RFID door entry.

Issue and revoke access without provisioning a full device.

LEARN MORE

Hideez Partner Program

Designed for VADs, system integrators, and managed service providers in IT security.

BECOME A PARTNER
FAQ

FAQs

Do we have to modify our application?

No. AuthShield runs in front of your app as a reverse proxy — the application itself stays untouched. There is no code change or rebuild.

Which applications are supported?

Any legacy web application. AuthShield is application-agnostic, and the Hideez team adapts it to your specific app.

Where is AuthShield deployed?

On a separate host in your DMZ, running under Nginx or Microsoft IIS. It keeps your back-end application off the public internet.

How are credentials protected?

Application credentials are stored on Hideez Enterprise Server (HES) and supplied to the app server-side. They are never exposed to the browser, so phishing and browser malware have nothing to capture.

Can it cover multiple applications?

Yes. Run one AuthShield instance per application, with multiple instances on the same host using different ports.

How does AuthShield handle security and compliance?

Credentials stay on Hideez Enterprise Server and never reach the browser, cutting phishing and credential-theft risk. AuthShield uses standards-based OIDC and runs as a hardened reverse proxy in your DMZ, keeping the legacy app off the public internet and supporting your existing security and audit controls.

How is AuthShield licensed?

AuthShield is an optional add-on to Hideez Workforce Identity — licensed per legacy web application and billed annually, in addition to your Hideez user licenses. Contact sales for a tailored quote.

More questions? Contact Sales
Get started

Bring modern authentication to the apps you can't replace

See how AuthShield adds passwordless SSO and 2FA to your legacy web applications — without rebuilding them.