If you need to capture the on-prem credentials during logon, you could achieve that with nFactor, but I think that's not a valid option end uesr-wise. The best option would be to have the internal applications modernized so that they accept SAML/OIC. Then you just need to decide whether to use the GW/AAA as the IdP or the AAD. Latter one is more common I think.