UniFi Access - Configure and Assign Access Policies
2023-12-05 16:25:51 UTC
You can create an access policy to set a time frame during which users can access designated locations, and then assign the access policy to users.
Create an Access Policy
UniFi Access
The Access application automatically generates the following default policies once the application is configured.
- If you set up the Access application running before v1.21.4:
- Default Admin Policy: Allow admins to access all locations anytime.
- Default UniFi Console Policy: Allow non-admin users to access all locations from Monday to Friday, from 9:00 AM to 6:00 PM.
- If you set up the Access application running 1.21.4 or later:
- Default Site Policy: Allow non-admin users to access all locations from Monday to Friday, from 9:00 AM to 6:00 PM.
- Go to your Access application > Settings > Policies > User Entry Policies.
- Click + New Policy, specify the policy name, and click Select Locations.
- Select location hubs or door groups and click Add Location.
- In the Schedule section, select “Always“ or ”Custom“.
- Always: Allow users to access the selected locations at any time.
- Custom: Specify a time frame during which users can access the selected locations.
- If you select Custom, perform the following actions based on your tasks.
- Add an access period: Hover your mouse over the “Not allowed to visit” period and click Add Schedule.
- Edit an access period: Use the drag-and-drop to edit or hover your mouse over a period and click the Ellipsis icon > Edit.
- Delete an access period: Hover your mouse over a period and click the Ellipsis icon > Delete.
- Use a different schedule during holidays: Tick the Set Holiday Schedule checkbox, click Add Holiday, and specify the holidays and schedules.
- Save the customized schedule as a predefined schedule: Tick the Save as a Predefined Schedule checkbox.
- Click Create.
UniFi Identity Enterprise
Identity Enterprise admins can create and edit access policies both in the UniFi Access application and Identity Enterprise Manager.
- Go to your Identity Enterprise Manager > Services > Door Access.
- Select a site, go to Policy, and click the “+” icon.
- Specify the policy name, and assign the locations and users.
- Do either of the following to specify the schedule:
- Customize the schedule by performing the following tasks.
- Add an access period: Hover your mouse over the “Not allowed to visit” period and click the “+” icon.
- Edit an access period: Use the drag-and-drop to edit or hover your mouse over a period and click the Ellipsis icon > Edit.
- Delete an access period: Hover your mouse over a period and click the Ellipsis icon > Delete.
- Use a different schedule during holidays: Tick the Set Holiday Schedule checkbox, click Add Holiday, and specify the holidays and schedules.
- Save the customized schedule as a predefined schedule: Tick the Save as a Predefined Schedule checkbox.
- Tick the Use a Predefined Schedule checkbox and select a schedule you previously created. The “Always Allow Access” schedule is created by default, which allows authorized users to access doors anytime.
- Customize the schedule by performing the following tasks.
- Click Create.
Assign Access Policy
UniFi Access
- Go to your Access application > Users. If your UniFi OS version is 3.2.5 or later, the system will direct you to the OS Settings > Admins & Users page.
- Go to the Users or Groups tab.
- Select a user or group and click Settings.
- Assign door access policies and other resources as needed.
UniFi Identity Enterprise
If UniFi Identity Enterprise is activated, access management for users will be centralized in the Identity Enterprise Manager. Consequently, it will not be possible to assign policies to users through the Access application or OS Settings. Do either of the following to assign policies:
- Go to your Identity Enterprise Manager > Services > Door Access > select a site > Policy > Assigned Users.
- Go to your Identity Enterprise Manager > Organizations > Members > Users > select a user > Permissions.
- Go to your Identity Enterprise Manager > Organizations > Members > Groups > select a group > Permissions.