UniFi Management

Operate a central UniFi controller for multiple customers

A central management platform can significantly simplify operations across many customer sites. It requires clean role design, documented assignment and controlled update and backup processes.

A single UniFi controller is quick to set up. With multiple customers and sites, however, recurring operational issues appear: versions differ, backups are stored in different places, credentials are inconsistent and it is not immediately clear which controller belongs to which customer.

A centrally operated management platform can reduce these problems. It does not, however, remove the need for secure permissions and documented customer structures.

Why a central platform can make sense

For an IT provider, the main benefits are in day-to-day operations:

  • One central access point for the support team
  • Consistent version and maintenance state
  • Structured assignment of customers and sites
  • Central backup of the management platform
  • Faster overview during incidents and changes

The network devices remain at the customer sites. The central platform serves as the management and configuration layer.

Sites provide organisational separation — not absolute isolation

Customers and locations are organised within separate sites or comparable structures. This simplifies navigation and permissions. However, an operator should not assume that every logical site automatically provides the same isolation as a completely separate platform.

For particularly sensitive customers, a dedicated instance may be more appropriate. The decision depends on risk, access requirements, contractual obligations and the desired level of independence.

Design roles and access restrictively

The biggest advantage of a central platform — one access point for many customers — is also a significant risk. Administrative permissions should therefore follow the principle of least privilege.

  • Personal accounts instead of shared logins
  • Two-factor authentication where available
  • Roles aligned with support, project work and administration
  • Regular review and removal of former staff accounts
  • Customer access only to explicitly assigned areas

External remote access and the adoption of new devices should also be documented. A device accidentally assigned to the wrong customer can quickly create unnecessary work.

Plan updates, backups and availability

A central platform affects many customers at once. Updates should therefore not be installed without review. A sensible process includes:

  1. Review of the intended version and known limitations
  2. Current backup before major changes
  3. Defined maintenance window
  4. Verification of login, sites and device connections after the update
  5. Documentation of the current version

Backups protect the management configuration, but they do not replace local documentation of important network parameters. Emergency access details, VLAN plans and device inventories should not exist only inside the platform.

The management platform is a particularly sensitive system

Depending on their role, anyone with controller access can make far-reaching network changes. Secure administration, restricted exposure and continuous monitoring are therefore essential.

Important:

A central UniFi platform should not expose unrestricted administrative access to the internet. An access concept, strong authentication and regular review are part of basic operations.

It is also necessary to clarify which telemetry and location data is visible on the platform and which contractual or data-protection requirements apply to individual customers.

White-label operation under the IT provider’s domain

The central access point can be provided under a domain of the IT provider, for example unifi.yourcompany.ch. This keeps the platform consistent across documentation and support.

White-label does not necessarily mean every vendor reference disappears completely. What matters is that the domain, contact path and customer relationship remain with the responsible IT provider and that the platform operator’s role is clearly defined.

Conclusion: centralisation requires discipline

For IT providers with multiple UniFi customers, a central platform can make operations significantly easier. The benefits come from consistent access, structured sites, predictable updates and central backups.

To prevent centralisation from becoming a central point of risk, permissions, documentation, update processes and recovery need to be designed from the outset.

Partnership

Offer cloud services under your own brand.

Discuss your use case directly with the people who operate the platform.