Unifi Identity VPN with MFA Setup¶
Source: _imported/Unifi/Unifi Identity VPN with MFA.txt · Applies to: All clubs using Unifi Identity Enterprise VPN · Last reviewed: 2026-07
Purpose¶
Guide users through setting up and connecting to the Unifi Identity Enterprise VPN with multi-factor authentication (MFA).
Prerequisites¶
- User is a member of the VPN Unifi AD group in the club's Active Directory.
- Microsoft Authenticator app installed on a mobile device.
- Work email accessible for optional second MFA method.
Steps¶
- Open a browser and navigate to the club's Unifi Identity portal (e.g.,
<club-name>.ui.com). - Click Sign in with Microsoft (or Sign in with Office 365).
- When prompted to set up MFA, open Microsoft Authenticator and scan the QR code.
- The prompt may reference Google Authenticator — Microsoft Authenticator works identically; ignore the label and scan with Microsoft Authenticator.
- Optionally, register your work email as a second MFA method.
- Download and install Unifi Identity Enterprise (Windows or Mac).
- Mobile app usage is disabled by default.
- Launch Unifi Identity Enterprise and enter the club's Identity name (e.g.,
<club-name>.ui.com) when prompted, then follow the on-screen prompts. - Once logged in, enable VPN in the Unifi Identity Enterprise client.
- Authenticate when prompted (MFA via Microsoft Authenticator).
-
Delete the old L2TP VPN configuration from the device if one exists.
-
[ ] User added to VPN Unifi AD group
- [ ] Microsoft Authenticator installed and MFA enrolled
- [ ] Work email registered as secondary MFA method (optional)
- [ ] Unifi Identity Enterprise installed
- [ ] VPN enabled and connection verified
- [ ] Old L2TP VPN config deleted
Notes / Gotchas¶
- The MFA setup screen mentions Google Authenticator, but Microsoft Authenticator works fine — scan the same QR code with either app.
- The Unifi Identity Enterprise mobile app is disabled by default; only desktop clients (Windows/Mac) should be used unless otherwise configured.
- Always remove any legacy L2TP VPN profiles after migrating to Unifi Identity VPN to avoid connection conflicts.