Involving External Stakeholders in On-Premise Processes: Connect Suppliers, Applicants, and Customers Without a VPN
Azure-based access and the FireStart hybrid approach compared – with guidance on architecture, access, data flows, and privacy
Connect suppliers, applicants, and customers to on-premise processes: Azure-based access and the FireStart hybrid approach compared, with access and privacy considerations.
Involving suppliers, applicants, or customers in an on-premise process is one of the most persistent challenges in process automation. This article compares two ways to cross the organisational boundary: Azure-based access and the FireStart hybrid approach. Both can enable external interaction without a traditional VPN connection.
The problem: The process ends at the organisational boundary
Many digital processes remain digital only inside the company's own IT landscape. A supplier emails master data and someone retypes it into the ERP system. An applicant sends a CV to a personal inbox. A customer calls because there is no form they can complete directly.
The pattern is consistent: internally, the process may already be automated with clear roles, approvals, and connected systems. As soon as a step involves an external person, the chain breaks and someone manually carries the data across the boundary. This gap costs time and can introduce transcription errors.
Why a VPN or directly exposed system often is not the right fit
A VPN connection for an external supplier or a guest account for an applicant is technically possible, but is often disproportionate for a one-off form submission. IT teams would need to manage access, endpoint requirements, and account lifecycles for people outside their organisation.
Making an on-premise system directly reachable from the internet also creates additional requirements. Interfaces and ports must be minimised, authenticated, patched, monitored, and included in the security design. It is therefore worth considering front-end or hybrid architectures rather than exposing the internal system by default.
Two ways to involve external stakeholders
Both approaches create an externally accessible interaction layer, but differ in platform, responsibilities, and their connection to the on-premise process.
Option 1: Azure as a possible bridge
In an established Microsoft Azure landscape, an Azure-based access layer may be an option for providing external forms or tasks without a traditional VPN client. Possible building blocks include controlled web access, identity services, gateways, or integration components. The appropriate Azure services and the implementation of authentication, network paths, permissions, logging, and safeguards depend on the organisation's system landscape.
Dominik Bachmair from ACP Cubido will demonstrate this approach in the FireStart Masterclass on Wednesday, 18 November 2026, and explain where organisations with existing Azure infrastructure can start.
Option 2: The FireStart hybrid approach
With the FireStart hybrid approach, the existing on-premise installation remains part of the system landscape. External users complete forms or tasks through FireStart Cloud. The implementation design must clarify how this cloud interaction connects to the internal process, which data is processed or stored in the cloud, and which network connections are required.
This can provide an external user interface without giving each external person traditional VPN access to the corporate network.
Which approach fits which situation?
- Azure is already established and cloud expertise is available: Azure-based access can build on existing identity, integration, and operating models.
- FireStart Suite already runs on premise: The hybrid approach can add external forms or tasks through FireStart Cloud while retaining the existing installation in the landscape.
- Several external groups are involved: Approaches can be combined differently based on protection needs, contact frequency, identity requirements, and existing architecture.
Where this comes up in practice
The gap at the organisational boundary appears repeatedly in similar use cases:
- Supplier onboarding and checks: New suppliers enter master data, upload evidence, and submit it directly into the intended review process.
- Application documents: CVs and application details arrive in a structured form instead of exclusively as attachments in a personal inbox.
- Customer enquiries and onboarding: Customers enter their own data; configured rules can detect duplicates and pass the details to the CRM.
- Contract approvals with electronic signatures: External partners can sign documents electronically. The required signature type depends on the document and use case. Read more in the Masterclass session on approvals and electronic signatures.
See FireStart solutions and use cases for more examples.
Frequently asked questions
Do external users need VPN access to take part in an on-premise process?
Not necessarily. An Azure-based access layer or external forms and tasks through FireStart Cloud can enable participation without a traditional VPN client. Whether accounts, additional authentication, or other access controls are required depends on the protection needs and specific architecture.
Does the on-premise server have to be directly reachable from the internet?
Not necessarily. Front-end and hybrid architectures can avoid or limit direct exposure. The incoming and outgoing connections, ports, gateways, or integration components actually required must be assessed and documented for the chosen Azure or FireStart architecture.
What should be considered for privacy and GDPR?
Organisations should clarify purpose and legal basis, affected data categories, roles and access rights, retention and deletion periods, hosting locations, processing steps in cloud and on-premise systems, and technical and organisational measures. Data processing agreements may be required depending on the parties involved. Sub-processors and possible international data transfers must also be assessed. A blanket compliance claim cannot replace an evaluation of the specific process.
What if suppliers, applicants, and customers all need to be involved?
Both approaches can be planned in parallel for different audiences. For each group, assess data sensitivity and volume, contact frequency, identity-verification needs, permissions, and retention periods separately.
Can I attend the Masterclass if I am not yet a FireStart customer?
The Masterclass is intended for existing FireStart customers. If you would first like to learn about FireStart, book a demo.
Conclusion
The manual gap in an otherwise digital process often appears at the organisational boundary. Azure-based access and the FireStart hybrid approach offer two ways to involve external users without a traditional VPN connection. The right option depends on the existing landscape, the data involved, and the access and operating requirements.
Dominik Bachmair from ACP Cubido and FireStart will discuss both approaches in practice on Wednesday, 18 November 2026, in the FireStart Masterclass. Register for the Masterclass.
If you are not yet familiar with FireStart, you can book a demo.
FireStart wird in der EU gehostet (DSGVO-konform, EU-Datenspeicherung). Website: www.firestart.com. Kontakt: sales@firestart.com.