Hideez AuthShield: Passwordless MFA & SSO for Legacy Apps
Give users passwordless, phishing-resistant MFA and single sign-on on the legacy and on-premises web apps modern IAM can't reach — through a secure access gateway, with no code changes.


Your legacy apps weren't built for modern security
Most business-critical apps were built before modern identity standards existed, so securing legacy authentication usually means a costly rebuild — or living with password risk.
- Can't connect to modern IAM or SSO
- Adding passwordless MFA usually means a rebuild
- Replacing the app isn't realistic
- Manual passwords keep the door open to phishing
What Is Hideez AuthShield?
Hideez AuthShield is an authenticating reverse proxy — a secure access gateway that brings passwordless MFA and SSO to legacy web applications, connecting them to Hideez Enterprise Server (HES).
It gives users passwordless, phishing-resistant MFA and single sign-on to applications that were never built for modern identity, without rebuilding or replacing them. The app's credentials stay on HES and are supplied server-side, so they never reach the user's browser.

A secure access gateway between your users and your app
Intercept
AuthShield catches the user's sign-in request before it reaches the legacy app.
Authenticate
The user is verified on Hideez Enterprise Server with passwordless, phishing-resistant MFA (over OIDC).
Retrieve
AuthShield pulls the app's stored credentials securely from HES, server-side.
Sign in
It submits the app's stored credentials for the user, server-side.
Redirect
The application session is created and the user is seamlessly redirected in.




































Modern authentication for legacy apps — without a rebuild
Passwordless MFA for legacy apps
Phishing-resistant, passwordless sign-in on apps that never supported it — no password to type, and nothing for attackers to phish.
Credentials secured on HES
Stored server-side and supplied for the user — they never reach the browser, so browser malware can't steal them.
OIDC-standard authentication
Built on OpenID Connect — standards-based, so it fits alongside the identity tools you already run.
Nginx / Microsoft IIS reverse proxy
Deploys as a hardened front-end layer inside your DMZ — no exposure of the back-end app.
Multi-app ready
Run one AuthShield instance per application, with many instances on a single host.
Adapted by Hideez
Our team tailors AuthShield to your specific legacy application, fast.
With vs without AuthShield
| Without AuthShield | With AuthShield | |
|---|---|---|
| Sign-in | Password + one-time code | Passwordless MFA (phishing-resistant) |
| Credential exposure | Typed in the browser (phishable) | Stored on HES, never in the browser |
| Changes to your app | Rebuild or replace | None — app untouched |
| Central identity & MFA | ||
| Time to value | Months (rebuild) | Fast (proxy adaptation) |
Where teams deploy AuthShield
Legacy & in-house web apps
Custom or vendor applications that can't integrate with modern IAM and won't be rebuilt.
On-premises internal portals
Intranet and back-office web apps you keep off the public internet.
During an IAM migration
Protect and keep legacy apps running while you roll out modern identity.
Regulated / restricted environments
Credentials stay on your Hideez Enterprise Server — never in the browser or a third-party cloud.
Part of the Hideez Workforce Identity platform
AuthShield is one part of the Hideez Workforce Identity platform. Explore the products that work together to make your workforce passwordless.

The control center of the platform — manage users, credentials, app integrations, workstation policies, and a full audit trail from one console, deployed as SaaS, private cloud, or on-premises.
Provision and deprovision users, rotate credentials, and enforce policies across every connected app and workstation from one place.
See who signed in, where, and when, with exportable logs that support your compliance and security reviews.
Run as SaaS, private cloud, or on-premises to meet your data-residency and regulatory requirements.

Turns a smartphone into a secure identity key: employees sign in to Windows workstations and business apps with a tap, and proximity can lock the PC when they step away.
Unlock Windows PCs with a phone tap instead of a typed password.
The workstation locks automatically when the paired phone moves out of range.
Fast, personal sign-in on shared workstations in healthcare, manufacturing, and retail.

Phishing-resistant FIDO2 / WebAuthn sign-in using device biometrics or a security key — no shared secret to steal, built on open standards that work across modern browsers.
Public-key credentials can't be reused or captured by fake sign-in pages.
Users sign in with the fingerprint or face unlock already on their device.
Built on FIDO2 / WebAuthn, so it works with modern browsers and identity providers.

Compact hardware security keys combining Bluetooth, NFC, RFID and USB in one device — passwordless access to apps and physical doors, ideal where phones aren't allowed.
A hardware key for secure areas where smartphones are restricted.
One credential for app login and RFID door entry.
Issue and revoke access without provisioning a full device.
Hideez Partner Program
Designed for VADs, system integrators, and managed service providers in IT security.
BECOME A PARTNERFAQs
Do we have to modify our application?
No. AuthShield runs in front of your app as a reverse proxy — the application itself stays untouched. There is no code change or rebuild.
Which applications are supported?
Any legacy web application. AuthShield is application-agnostic, and the Hideez team adapts it to your specific app.
Where is AuthShield deployed?
On a separate host in your DMZ, running under Nginx or Microsoft IIS. It keeps your back-end application off the public internet.
How are credentials protected?
Application credentials are stored on Hideez Enterprise Server (HES) and supplied to the app server-side. They are never exposed to the browser, so phishing and browser malware have nothing to capture.
Can it cover multiple applications?
Yes. Run one AuthShield instance per application, with multiple instances on the same host using different ports.
How does AuthShield handle security and compliance?
Credentials stay on Hideez Enterprise Server and never reach the browser, cutting phishing and credential-theft risk. AuthShield uses standards-based OIDC and runs as a hardened reverse proxy in your DMZ, keeping the legacy app off the public internet and supporting your existing security and audit controls.
How is AuthShield licensed?
AuthShield is an optional add-on to Hideez Workforce Identity — licensed per legacy web application and billed annually, in addition to your Hideez user licenses. Contact sales for a tailored quote.
Bring modern authentication to the apps you can't replace
See how AuthShield adds passwordless SSO and 2FA to your legacy web applications — without rebuilding them.