Skip to content

Unifi Identity VPN with MFA Setup

Source: _imported/Unifi/Unifi Identity VPN with MFA.txt · Applies to: All clubs using Unifi Identity Enterprise VPN · Last reviewed: 2026-07

Purpose

Guide users through setting up and connecting to the Unifi Identity Enterprise VPN with multi-factor authentication (MFA).

Prerequisites

  • User is a member of the VPN Unifi AD group in the club's Active Directory.
  • Microsoft Authenticator app installed on a mobile device.
  • Work email accessible for optional second MFA method.

Steps

  1. Open a browser and navigate to the club's Unifi Identity portal (e.g., <club-name>.ui.com).
  2. Click Sign in with Microsoft (or Sign in with Office 365).
  3. When prompted to set up MFA, open Microsoft Authenticator and scan the QR code.
  4. The prompt may reference Google AuthenticatorMicrosoft Authenticator works identically; ignore the label and scan with Microsoft Authenticator.
  5. Optionally, register your work email as a second MFA method.
  6. Download and install Unifi Identity Enterprise (Windows or Mac).
  7. Mobile app usage is disabled by default.
  8. Launch Unifi Identity Enterprise and enter the club's Identity name (e.g., <club-name>.ui.com) when prompted, then follow the on-screen prompts.
  9. Once logged in, enable VPN in the Unifi Identity Enterprise client.
  10. Authenticate when prompted (MFA via Microsoft Authenticator).
  11. Delete the old L2TP VPN configuration from the device if one exists.

  12. [ ] User added to VPN Unifi AD group

  13. [ ] Microsoft Authenticator installed and MFA enrolled
  14. [ ] Work email registered as secondary MFA method (optional)
  15. [ ] Unifi Identity Enterprise installed
  16. [ ] VPN enabled and connection verified
  17. [ ] Old L2TP VPN config deleted

Notes / Gotchas

  • The MFA setup screen mentions Google Authenticator, but Microsoft Authenticator works fine — scan the same QR code with either app.
  • The Unifi Identity Enterprise mobile app is disabled by default; only desktop clients (Windows/Mac) should be used unless otherwise configured.
  • Always remove any legacy L2TP VPN profiles after migrating to Unifi Identity VPN to avoid connection conflicts.