Winserv WiFi corporate sign-in for UniFi (Ubiquiti) Wi-Fi

Identity governance for corporate Wi-Fi

Entra ID sign-in with MFA
for your UniFi Wi-Fi.

When someone leaves, their access leaves too.

Corporate Wi-Fi sign-in through Microsoft Entra ID, formerly Azure AD (OIDC + MFA) — no on-prem Active Directory, no RADIUS, no NPS, no PKI. Employees sign in once and stay connected for 30 days; when they leave the group or the company, their network access is cut within minutes.

UniFi only. It works on top of a UniFi Controller (Ubiquiti) — that is where the portal authorizes devices. It does not work with other vendors' access points: if your Wi-Fi is not UniFi, this product is not for you.

To set it up yourself you need to be a Microsoft Entra ID administrator in your company, and your UniFi Controller must be reachable from the internet. See the requirements.

Runs on Winserv infrastructure · Microsoft authenticates, we only orchestrate

Offboarding in minutes, not in 30 days

The difference is not the sign-in — it is the offboarding. The 30 days are a convenience for people who are still with you, not a grace period for people who left: every few minutes the portal reconciles the authorized group in Entra ID and cuts Wi-Fi for anyone who no longer belongs to it. On top of that, group membership is checked again at every renewal, and an operator can revoke a user from the console, which disconnects all of that person's devices at once. This is corporate identity governance, not guest marketing.

Why it is different

Real MFA and Conditional Access

Entra ID challenges the user with the MFA and policies you already have. The portal only orchestrates the OIDC flow; device-based policies (compliant device) need the portal's app excluded, because a captive-portal browser cannot present the device.

Sign in once · 30 days

While an employee is active, the device stays authorized for 30 days with silent renewal — sign in once and forget the portal. The window follows the employment: people who leave lose access in minutes, not in 30 days.

Nothing to run

A managed service: no server, no VPN and no UDP to open. The portal talks to your controller over HTTPS, and nothing else on your network changes.

How it works

  1. Connect. The device joins the open SSID and lands on the captive portal.
  2. Microsoft sign-in + MFA. Entra ID runs the challenge, with your Conditional Access policies.
  3. Authorize. The portal lets the device in on the UniFi controller (authorize-guest).
  4. 30 days while active. Silent renewal, no new sign-in. People who leave are cut within minutes, whatever the window. And if the portal goes down, people already connected stay connected: UniFi keeps the device table.

What it replaces

BeforeAfter
On-prem AD + NPS + RADIUSA managed service — nothing to install
Windows Server (licences + CALs)Nothing — it uses the Entra ID you already pay for
A VPN so branch offices reach the ADHTTPS over the internet
A certificate per device (PKI)Open SSID + captive portal with native MFA
Domain controller upkeepNothing — Microsoft runs the identity

Pricing

Winserv WiFi

US$ 69/month · 14-day trial

Up to 50 people with active access. Unlimited devices. One UniFi site per portal. No setup fee for self-service.

  • OIDC + MFA through Entra ID
  • Guest vouchers, self-hosted
  • Silent renewal (30 days)
  • Offboarding revocation
  • Pre-registration API (Intune)
  • 8×5 support, business hours in Brazil (UTC−3)

More than 50 people: up to 100 for US$ 99, up to 250 for US$ 249, up to 500 for US$ 499 a month. The trial starts on the 50 tier; if your team is larger, the tier is adjusted at the end of the trial from the count you see in your own console. Over 500, or many sites? Talk to Winserv.

Companies in Brazil are billed in reais — preços em português.

Frequently asked questions

Does a former employee keep access for 30 days?

No. The 30 days are the convenience of not signing in again while the person is active. Once they are removed from the group or disabled in Entra ID, automatic reconciliation cuts their access within minutes — and an operator can revoke all of their devices at once from the console.

Do I need Active Directory, RADIUS or Windows Server?

No. The identity is the Microsoft Entra ID you already use. No domain controller, no NPS, no RADIUS.

Do I need a Microsoft 365 license for everyone who uses the Wi-Fi?

No. Sign-in uses Microsoft Entra ID, whose free edition comes with any Microsoft 365 or Azure subscription and includes sign-in to unlimited apps. Each person needs an account in your company's Entra ID and to be in the authorized group; no Microsoft 365 or Office license needs to be assigned to them.

Does MFA require Entra ID P1 or P2?

No. Entra ID's security defaults are free: when they are on, everyone registers for MFA with an authenticator app (such as Microsoft Authenticator), and Microsoft prompts for it when it judges a sign-in needs it. To require MFA on every sign-in, or to set your own rules, you need Conditional Access, which requires Entra ID P1, included in Microsoft 365 Business Premium, E3 and E5. The portal applies the rules your Entra enforces at sign-in and charges nothing extra for it. The exception is device-based rules (compliant or hybrid-joined device): a captive-portal browser cannot present the device, so exclude the portal's app from those policies.

What about guests: visitors and Entra guest accounts?

A visitor with no account in your company gets in with a voucher — no Microsoft sign-in, and not counted in your plan. A guest account (B2B, guest type) that you put in the authorized group gets in like an employee, signing in with their own company's account, and counts as a person in your plan. Microsoft bills guests by monthly active user; the first 50,000 are free.

Does it need a VPN, a public IP for RADIUS, or UDP?

No. Everything runs over HTTPS: the portal reaches your controller's API over HTTPS, and devices reach the portal over HTTPS. It works behind CGNAT and on satellite links.

What if the portal goes down?

People who are already signed in do not notice. The UniFi controller keeps devices authorized for 30 days; only new sign-ins and renewals wait until the portal is back.

Does Winserv see users' passwords?

No. Authentication happens at Microsoft; the portal only orchestrates the OIDC flow and receives a token. Passwords and MFA never pass through us.

Which access points and controllers are supported?

UniFi Network (Ubiquiti) only, tested on UniFi Network 10.0, 10.4 and 10.6 and on UniFi OS Server, with an open SSID and the captive portal. It does not work with other vendors' controllers. Your UniFi controller stays on your side, reached over HTTPS.

Ready to take RADIUS out of the picture?

Create your portal yourself in a few minutes — or, if you would rather talk first, a 20-minute call to see whether it fits your controller.