Microsoft Web Application Proxy [WAP] is a service in Windows Server 2022 that allows you to access web applications from outside your network. WAP functions as a reverse proxy and an Active Directory Federation Services [AD FS] proxy to pre-authenticate user access.
For the user, it provides seamless sign on using the same, familiar account credentials.
For the developer, it provides an easy way to authenticate users whose identities live in the organizational directory so that you can focus your efforts on your application, not authentication or identity.
Eliminate Passwords from the Extranet
Sign in with AWS Multi-Factor Authentication
Password-less Access from Compliant Devices
Sign in with Windows Hello for Business
Secure Access to Applications
Modern Authentication
Configure access control policies without having to know claim rules language
Enable sign on with non-AD LDAP directories
Better Sign-in experience
Customize sign in experience for AD FS applications
Manageability and Operational Enhancements
Streamlined auditing for easier administrative management
Improved interoperability with SAML 2.0 for participation in confederations
Simplified password management for federated users
Highlights
Microsoft Web Application Proxy [WAP] is a service in Windows Server 2022 that allows you to access web applications from outside your network. WAP functions as a reverse proxy and an Active Directory Federation Services [AD FS] proxy to pre-authenticate user access.
Provide AWS Multi-Factor Authentication to your users when signing into federated applications
Provide sign on and access control to both modern and legacy applications, on premises and in the cloud, based on the same set of credentials and policies.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier for more details.
You pay by the hour for this Web Application Proxy (WAP) 2022 server, running as a Windows Server image on an EC2 instance. Pricing is not tiered by feature. Instead, each dimension maps to a specific EC2 instance type, from small burstable sizes like t2.nano and t3.micro up to memory-optimized, compute-optimized, and GPU sizes such as x1e.32xlarge and p3dn.24xlarge. Your cost scales with the instance you choose: larger instances with more CPU, memory, or storage carry higher hourly rates. You select the instance that fits your workload and pay only for the hours you run it.
Top-of-mind questions for buyers
What exactly am I paying for with each hourly instance dimension?
You pay for one running EC2 virtual machine per hour, preloaded with the WAP 2022 Windows Server image. The dimension name matches the EC2 instance type you launch. Each instance size defines the CPU, memory, and storage available. You pay the hourly software rate plus the underlying AWS infrastructure charge.
Am I charged the hourly rate when the WAP server is stopped or powered off?
The hourly software charge meters running time only, so a fully stopped instance does not accrue it. However, a stopped instance may still incur AWS storage fees for its attached disk. To avoid all charges, you must terminate the instance rather than just stop it.
How do I decide which instance dimension to pick for my WAP server?
Choose the instance based on expected traffic through the Web Application Proxy. Burstable sizes like t2.nano or t3.micro suit small or lab setups. Larger compute, memory, or GPU instances suit heavier, continuous traffic. You can start small and switch to another instance type later as needs change.
cloudinfrastructureservices.co.uk
Helpful?
Vendor refund policy
We do not currently support refunds, but you can cancel at any time.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Latest OS patches installed. Simply run Windows update to install the latest Microsoft patches
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This product has charges associated with the pre-built hardening to the CIS Benchmarks™ and recurring maintenance. The CIS Hardened Images® are hardened in accordance with the associated CIS Benchmarks, an industry best practice for secure configuration. Reduce cost, time, and risk by building your AWS solution with CIS AMIs.
This product has charges associated with the pre-built hardening to the CIS Benchmarks™ and recurring maintenance. The CIS Hardened Images® are hardened in accordance with the associated CIS Benchmarks, an industry best practice for secure configuration. Reduce cost, time, and risk by building your AWS solution with CIS AMIs.
This product has charges associated with the pre-built hardening to the CIS Benchmarks™ and recurring maintenance. The CIS Hardened Images® are hardened in accordance with the associated CIS Benchmarks, an industry best practice for secure configuration. Reduce cost, time, and risk by building your AWS solution with CIS AMIs.
This product has charges associated with the pre-built hardening to the CIS Benchmarks™ and recurring maintenance. The CIS Hardened Images® are hardened in accordance with the associated CIS Benchmarks, an industry best practice for secure configuration. Reduce cost, time, and risk by building your AWS solution with CIS AMIs.
This product has charges associated with the pre-built hardening to the CIS Benchmarks™ and recurring maintenance. The CIS Hardened Images® are hardened in accordance with the associated CIS Benchmarks, an industry best practice for secure configuration. Reduce cost, time, and risk by building your AWS solution with CIS AMIs.
ADFS WAP 2016 helps to secure your ADFS external users authentication
Reviewed on Mar 11, 2024
Review provided by G2
What do you like best about the product?
Using ADFS WAP were able to redirectly our exteranl users to securily to use the ADFS servers without exposing it to internet. It seamlessly works and integrate with ADFS server. It is easy to use and have basic configuration to make it ready.
What do you dislike about the product?
I don't see any major downside however just an issue which i observed is that trust broken between adfs and adfs wap while renewing SSL certificate.
What problems is the product solving and how is that benefiting you?
It is helping us to keep our internal resources secure from external/internet threats. By using ADFS WAP we were able to redirect our external users to contact to WAP in DMZ zone first without exposing internal ADFS server.