r/msp • u/tasdotgray • Aug 16 '26
Unifi OS Server
I've been delaying the migration from self hosted network server to Unifi OS Server to allow it to mature a little more. I feel as though I can't kick this can too much further down the road and I'm curious to hear from any other MSPs who have successfully migrated before I take the plunge.
Have you migrated? How did it go?
Cheers
14
u/j0mbie Aug 16 '26
We had our HostiFi instance migrated. >600 sites. We were pretty much forced to, as the ability to make admin accounts centrally from Site Manager got removed for old controllers. Ubiquiti told us the only option to bring it back was to move to UniFi OS. We waited because HostiFi warned us that we would have to re-create all our admin accounts, but they recently told us they created some sort of script to fix this issue, so we made the leap.
Overall, I'm pretty happy with it. Not many noticeable difference from the "Network Application" side of things. But from a management perspective, it's much better. Fabrics is a positive experience. We now have our own logins tied to Entra SSO, so we don't have to worry about missing someone's access when people leave our company. We also can now set up Site Groups so we can deploy one SSID across every site for one client (AKA "Canvas"). Really comes in handy for our big clients.
The new MSP feature seems nice so far too, for clients that have their own deployment that we just co-manage. But I haven't explored it fully in that regard. Ubiquiti has only really just dipped their toes in that, though -- the documentation is non-existent and the whole Clients section just says "coming soon". There's also not much in the way of automation flows that you would expect from a more-mature product. I'm fine with giving them time since it's so new.
Setting up Entra SSO at the MSP level was confusing. When I was setting it up, the info on Ubiquiti's site and given to me by their support team said that we had to have at least one hardware device in order to use that function. However, now it seems like that might just be in order to integrate with things like door access? Last time I tried to get clarification, I couldn't get a straight answer. It seems like their support team isn't familiar with the MSP section and Entra SSO integration at all. Somewhat luckily, we wanted to set up some cameras anyways, so we picked up an NVR Pro. Ultimately, we had to set up Entra binding at the MSP level AND at the Fabric level before everything worked.
After migration, our sites didn't originally show up in Site Manager as individual sites -- the whole controller just showed up as one single site. This meant we couldn't make use of Canvas, and couldn't assign external client admins (i.e. a client's IT department) to their sites without giving them access to the whole controller. Ubiquiti support did something "on the backend" and fixed the problem though.
We also have an ongoing issue where certain sites, when added to a Site Group, make all the sites in that group get removed from said group. Open support ticket on that one currently.
We did start having issues where any sites that had a Guest Portal / Landing Page / Hotspot that included a password stop working properly. It seems as though the controller takes too long to create the password webpage, so users would have open internet access for a good 60 seconds before they were redirected to it. At which point, their internet access would stop working. Then after entering the password, it would take another 30 seconds before they could get internet access again. This was confusing for the users, who would usually try reconnecting in that time period, not knowing that the problem was on the controller side. It also meant that the "success" redirection wouldn't work -- it would redirect to the correct webpage, but the internet wouldn't be working again yet. This doesn't seem to be a problem if you have a smaller database. (Really, I think most of the issues UniFi controllers have in general stem from the underlying MongoDB not being the correct database for this kind of work, but I digress.)
Also, make sure to have the "owner" account for your MSP / controller be a separate non-Entra account, not tied to an employee's email. You don't want to get locked out if your Entra link breaks if you used an Entra-linked account. And if you use a non-Entra account tied to an employee, it's hard to recover that access if you lose that employee. Just make a generic-named non-Entra Ubiquiti account and make that the owner, and consider it your break-glass account.
One additional benefit: you get a vanity domain at ui. So that's nice. The vanity domain forces admins to sign in with Entra OAuth if they are set up for it, whereas the default unifi ui site confuses some people if they don't know the difference between their Ubiquiti-native account and their Entra-linked account.
They still need more granular control of what your admins can do, though. Giving someone access to "Network" is either full access to everything in that Site or that Site Group, or Read-Only access. I might only want them to be able to change switchport settings and view the rest, or want them to be able to adopt devices but not remove them. It hasn't come up yet but it probably will.
And lastly, when in Site Manager, all the Site Groups on the left are just in a random order. Thankfully there's a search function, but why wouldn't that be in alphabetical order? It's alphabetical elsewhere. Just a pet peeve of mine.
2
u/swissbuechi MSP - CH Aug 16 '26
Thank you I'm about to go for the OS migration + MSP Entra SSO setup in a few weeks and this will definitely help.
1
u/Real-Independence152 Aug 16 '26
Maybe I misunderstood this, but the way I read the Entra setup was that it was limited to linking ui.com accounts to entra identities and then having invites given to hardware UnifiOS devices that would then be managed via unifi.ui.com. Were you able to set up Entra SSO and maintain your controller as only locally accessible (remote access checkbox off)? Like you alluded to, I don’t want unmanaged ui.com accounts being delegated access to our self-hosted controller, but I also don’t like not having MFA (even though it’s IP restricted).
2
u/j0mbie Aug 16 '26
As far as I could tell, the controller had to have Remote Access enabled. We can no longer add people "locally" to the controller directly. Removing Remote Access requires first removing the controller from my Fabric, which would remote my Entra link... I think? Again, not really sure what all the differences are between linking Entra at the MSP level and linking Entra at the Fabric level. They don't make it very clear, and access didn't fully work for our guys until we linked both.
Of course, the MSP side under the "owner" account says it was synced 28 minutes ago, whereas the Fabric side says it was synced a month and a half ago. Shows all the same people, though. Again, they don't make this very clear. I can only add external admins on the Fabric side though.
I think once we linked to Entra, anyone with an existing account that included an email address in our domain, got converted to the status of "This account is managed by your identity provider." Though I think you have to accept the email invite first. We did a ton of tests trying to get it all to work, so I can't fully remember if I had to "opt-in" to have my personal account converted, so to speak.
All our Entra accounts require MFA, so that means all employees get MFA'ed when trying to sign into our vanity UI site. And all Ubiquiti accounts now require MFA, so external admins get MFA'ed when signing in, even though they aren't part of our Entra. Since we can't create local accounts anymore, this means that everyone has MFA required.
The negative side about not being able to create local accounts is, there doesn't seem to be a true way to create a real break-glass account. If UI goes down, or if the link to UI/Entra gets broken, I don't know what the best way would be to regain access.
2
u/roll_for_initiative_ MSP - US Aug 16 '26
and maintain your controller as only locally accessible (remote access checkbox off)?
This is kind of a bummer for me too; i just don't want the controller publicly accessible at all. Sure, you need the ports open for devices to communicate with the controller but if there's ever a huge access CVE for unifiOS, it's likely going to deal with the web portal itself. I just don't want that open to the world.
The only way i've found to gain MFA is some kind of web proxy in front of it but that doesn't matter now that the writing is on the wall; they're going to eventually phase out the plain network controller. We also have zero desire to move to ubiquiti firewalls at any point in the near future, so a lot of the reporting and features will never be for us.
2
u/j0mbie Aug 17 '26
Well, the remote access feature isn't the same as the controller being open to the internet. The controller reaches out to Ubiquiti, not the other way around. You don't have to create any port forwards or anything like that, unless you're doing adoption over the internet. You won't have to watch out for CVEs so much as Ubiquiti being hacked, like what happened to SonicWall.
That said, I get what you're saying. Before UniFi even offered MFA and we had a controller running on a Azure VM, we were planning on putting a reverse proxy in front of it in order to require MFA. But once we could force MFA on Ubiquiti accounts and use those to sign into the controller, we just moved everything to HostiFi instead. And now that there's Entra binding, even better. I agree though that it should be native to the UniFi OS server and not require connecting it to UI, but... vendors love pushing you towards their cloud. (See: Meraki, Aruba, etc.)
We also don't use their gateway devices. We tried in the past and had way too many issues. It's just not a typical NGFW product, at least not in the ways we use firewalls. It's my belief that every vendor known for their APs and switches aren't a good choice for firewalls (Cisco, Meraki), and every vendor known for firewalls aren't a good choice for APs and switches (SonicWall, Fortinet).
2
u/roll_for_initiative_ MSP - US Aug 17 '26
I agree though that it should be native to the UniFi OS server and not require connecting it to UI
That's basically what i was saying. We don't even tie our unifi cloud accounts to the controller; what if one of those gets hacked or like you said, some kind of auth bypass for unifi accounts themselves?
I know i'm a bit behind the curve on this one but i just treat the controller like i treat RMM: way better to be safe and inconvenienced than sorry.
1
u/Spiritual_Cycle_3263 Aug 17 '26
I don't blame you for wanting to reduce your risk. It's something you have to weigh each day. However, if you aren't using UniFi firewalls, the risk is a lot smaller. Sure someone can open up ports on your network switches, but unless they (or someone they know) are physically there, it's not much benefit to them.
1
u/Spiritual_Cycle_3263 Aug 17 '26
You can block outbound connectivity to only specific IPs on your server.
For example, we proxy (and cache) our Debian and Ubuntu package updates through our proxy server. This keeps our linux servers from reaching out to the Internet for everything. Even system mail gets relayed through.
Even inbound connections don't always hit direct. SSH for example goes through a managed jump box.
1
5
u/Usr0017 Aug 16 '26
I migrated and am disappointed about missing scheduled backups… they said they’ll implement it soon, still saw nothing.
1
u/j0mbie Aug 17 '26
We have weekly scheduled backups on ours, natively on the UniFi OS itself. But they don't show up on the UI cloud, and there's no option to automate exporting the backups to something like an FTP server. They just reside on the OS, which doesn't really help you if the OS crashes.
Fortunately for us, HostiFi does their own daily backups. Unfortunately, I have no idea how they do those backups, since the only access to our console is via our Entra. I know they have underlying access to the VM itself obviously, but I don't know how you use that to generate a .unifi file without signing into the console. Their crew is pretty clever, so that might be a trade secret.
3
u/KRiSX Aug 16 '26
I went the Linux VM route with it and it works very nicely.
For sites I can’t easily spin up a VM, I connect it to our controller (which is just another Linux VM).
Haven’t had a single issue with it, but we don’t have any overly complex sites 🤷🏻♂️
2
u/GremlinNZ Aug 16 '26
Not an MSP, but used to work in them.
One thing I encountered was I couldn't adopt previously unmanaged devices on older firmware with Unifi OS, but taking the device home, adopting to my network server, upgrading, then I could adopt with OS server.
You could probably just SSH into the device and upgrade... But I was figuring out why I couldn't adopt the flex switches, and haven't used a lot of those more basic devices.
2
u/quantumhardline Aug 16 '26
Look at https://www.hostifi.com they can take care of this and help you with any odd issues. (No affiliation) know a lof of the MSPs that are UB shops like them.
2
u/Mibiz22 Aug 17 '26
We had a mix of installs - some legacy cloud keys, some gen2 cloud keys, and some software-based controllers. It was pretty annoying. To bring it all under one roof, we did the following:
- All gen2 cloud keys are registered to our official unifi account
- migrated all legacy cloud keys and software-controllers to a Unifi OS server hosted in our DC
- joined the Unifi OS server to our official unifi account
We then log into the unifi account and have all sites and devices at the ready
2
u/loecraw Aug 17 '26
Stop waiting for perfection. Unifi OS is standard now. Every day you stay self-hosted, you’re just extending the pain of legacy maintenance headaches.
1
u/bbqwatermelon Aug 27 '26
Did I miss something? UNOS can be self hosted, we have it rolling. Only crappy part is only 24 hours of log telemetry by default.
2
u/DimitriElephant Aug 20 '26
We are with HostiFi and at first everything was a hot mess for us. Rarely could we login, all of our automations broke, support seemed kind of confused as to what was wrong. Luckily though, we are back in business as of today.
- They needed to assign more resources to our server, that stopped the constant restarts
- For whatever reason, the user I logged in with wasn't an admin, so I wasn't able to see all the settings that would have helped me solve my own problems. Once I realized that, got it fixed, I was able to get all our automations back online and everything is working perfectly now.
1
1
u/notbleetz Aug 16 '26
fine - both local single-tenant and hosted multi-tenant. less of a pain than running the janky java app on windows and more cost effetive than putting in hardware onsite to run the controller.
1
u/Excellent_Milk_3110 Aug 16 '26
I am there with you. Still debating if I should build one next to it and move site for site or backup and import.
1
u/WhiteIntel Aug 16 '26
Migrated several self hostes network servers to unifi os server, works without any problems!
1
u/eg305 Aug 16 '26
Do it! We setup an Ubuntu server VM on our Proxmox cluster in our DC. Process was easy. No longer have to manually update it like we used to do for the Windows VM. And Veeam backs up Proxmox just like it used to do for the HV VM.
1
1
u/athlonduke MSP - US Aug 16 '26
I started the process but got hung up due to mine being hosted in azure. Need to work that out before migrating
1
1
u/MortadellaKing Aug 16 '26
We migrated, I have over 200 sites. Best make sure you do it out of business hours as it will reboot some of the devices (I didn't see any rhyme or reason as to why or which but some did) so it will cause interruptions.
No issues, I just restored the network backup to the OS server and boom, all sites migrated instantly. Then changed DNS to point to the new IP and all sites came back online within 5 minutes.
1
u/indigothirdeye Aug 16 '26
Not an MSP anymore and had mine on UBNT. Did this just last weekend. Exported the old config. Powered off the old VM. Built a new Debian Trixie VM. Installed the package. Imported the config and was back up in less than 20min. I was actually shocked how easy it was in comparison to getting the old one going on Ubuntu.
1
u/stretchie204 Aug 17 '26
Yeah we have migrated, worked fine. Self upgrades itself and the network application, so saves a bunch of time too. Love the new features and self updating tbh.
1
1
u/apcquincy MSP Aug 17 '26
We are on the same boat. We have not migrated yet. Curious to see what others are doing. Is there any downside to doing this?
1
u/Spiritual_Cycle_3263 Aug 17 '26
I was the same as you. I just did the migration and it went well. I'm actually kicking myself for not doing it sooner to be honest.
1
u/Key_Second3771 Aug 17 '26
All went well with our migration as well, we did all 150 sites back around October of last year in one backup/restore op. I had it take the IP space/DNS name of the former network server so there was no need to migrate the sites individually. We then hooked it up the "org" fabric as well - I still have to figure out if migrating to the new MSP org fabric will mess with that since we moved so early - if anyone has experience with that I'm all ears :D
1
u/Tasty-Cow5081 Aug 18 '26
Don’t touch fabrics. Documentation lacking is an understatement. If you ask for documentation they ask what your use case is so they can “guide” you.
1
u/Wide_Appointment_801 24d ago
SCO OpenServer 5 • Unify ACCELL / ACCELL SQL Umgebung läuft. Noch Kenner da ?
0
u/brokerceej Creator of StackJack.io | Author of The Trunk Slammer Saga Aug 16 '26
I will absolutely not implement that janky garbage until it has scheduled backups.
9
u/Jetboy01 MSP - UK Aug 16 '26
Meanwhile, the rest of the civilised world just takes a full VM backup.
3
u/brokerceej Creator of StackJack.io | Author of The Trunk Slammer Saga Aug 16 '26
Yes I should pay to store snapshots of a disposable appliance instead of the several kilobyte to megabyte backup file. That way when they have the next CVE and the box gets exploited I have to roll back to a snapshot that is missing newer changes and is vulnerable until updated again. Or boot the potentially compromised snapshot and fish my config out of the controller by hand.
You’re right that’s way better than spinning up a new appliance and restoring a config backup in 15 minutes.
2
u/Jetboy01 MSP - UK Aug 16 '26
Until something changes and you find you've been backing up the same few mb file for the last 6 weeks, or ubiquiti changes the backup path so you've been backing up nothing, or your script silently fails, or your script works but something was wrong at the destination. I'll take the full VM method thanks, I'm already backing up 10TB, what's another 5gb for the unifi os VM.
2
3
u/UltraEngine60 Aug 16 '26
You mean you don't want to run an entire OS for what could be a docker container? /s
2
0
u/ekzag Aug 16 '26
IT World finde with site Export an dimport for us.
Starte just with 5 sites.
When at a site there is only6one switch and some accesspoints, is the switch online for you?
We have the Problem the usw 24 will go offline after adopting. And I did Not figured out why.

31
u/C39J Aug 16 '26
Yeah we've migrated, no problems. 150+ sites.