Ubiquiti/Unifi account confusion

Status
Not open for further replies.

cpk0

Ars Tribunus Militum
2,362
Subscriptor++
I know they have their own forum, but I like you guys better so I'm asking here first...

I've been using a basic Unifi setup for a while now, with two AP's and a controller running on Linux. I mostly get how that all works together. Now I'm setting up a new building and it's going to need to be able to get managed remotely, so I went all-in with Unifi gear: a Cloud Key, Security Gateway, POE switch, and some APs. I still have a good understanding of how to set it all up, but I'm starting to get confused with all the different accounts and credentials that I seem to have accumulated.

So for starters, in the controller there's one set of credentials that is the "Device Authentication", which is listed under Site settings. I don't really know what that's actually for. The site? The controller? The Cloud Key?

Then there are admins. My understanding is these are accounts completely local to the controller.

Then there are ubnt.com accounts, which are used to log in to unifi.ubnt.com, where controllers designated for Cloud Access show up. I have literally no understanding of what the association between unifi.ubnt.com and the controller accounts are. When turn on Cloud Access in the controller settings, I have to log in to some ubnt.com account, and it seems like that account immediately gets connected to the controller. Then I can also add a new (local?) admin account on the controller, which sends and invite to an email address that may or may not be associated with a ubnt.com account. Confirming that email sometimes will make the controller show up in that account's unifi.ubnt.com dashboard and...sometimes not.

There definitely seems to be some sort of connection or association that can happen between the local admin accounts and the cloud accounts, but I can't find a single thing that says how that all works. Right now I have either one or four different accounts with the same email address and maybe different passwords on various devices or services.

Can anyone help explain how these pieces all fit together?
 

gfunkdave

Wise, Aged Ars Veteran
152
I've been using Ubnt gear at home for all of the last two weeks, but this is my understanding.

Your Unifi Controller instance (which in your case resides on the Cloud Key) can have multiple local user accounts. In addition, you can associate a single ubnt.com account with your controller. This is done via the Cloud Access screen on the Settings page of the controller's web interface. You access all controllers associated with your ubnt.com account via https://unifi.ubnt.com

Ubnt.com uses a single account to access all services available there, so there isn't a plethora of different ubnt.com account types.

Oh, and the "Device Authentication" login details are the credentials to SSH into the Unifi APs and USG directly.
 

cpk0

Ars Tribunus Militum
2,362
Subscriptor++
I guess the part I don't get then is how I currently have two separate ubnt.com accounts that both show both controllers. I.e., if I log into the generic unifi@acme.com account at unifi.ubnt.com I see two controllers, and if I log in to cpk0@acme.com I see the same two controllers. If I look at Cloud Access on both controllers, the account associated is unifi@acme.com. How/what is making the controllers show up on cpk0@acme.com?
 

cpk0

Ars Tribunus Militum
2,362
Subscriptor++
So one thing I just noticed is that when I log in to unifi.ubnt.com as cpk0@acme.com, and then I "Launch Site" into one of the controllers, it does some sort of SSO handshake with the local controller, and I'm in the controller dashboard as the cpk0@acme.com local user. BUT ALSO if I then look at the Cloud Access settings page, it shows as being associated with the cpk0@acme.com UBNT account. So it is making a Cloud Access association *per local user* with different UBNT accounts, it's just very not obvious about doing so.
 
Status
Not open for further replies.