Creating an Organization in UniFi
UniFi Organizations simplify the management of multiple sites by providing centralized user management, SAML-based SSO, and scalable security policies. They integrate with your Identity Provider (IdP) and directory services, while enabling seamless control over user access, admin roles, and network policies.
To learn more, visit Introducing UniFi Organizations.
Getting Started
|
|
Creating a UniFi Organization is straightforward, but consider these key points first:
-
(Recommended) Use or Create a Dedicated, Company-Owned Email
- We recommend using a role-based, company-owned email to ensure smooth transitions in the event of personnel changes.
- In-House IT Teams: IT@mycompany.com
- MSPs: clientname@mycompany.com
- We recommend using a role-based, company-owned email to ensure smooth transitions in the event of personnel changes.
-
Transfer Ownership of Sites You Don’t Want Included
- All sites owned by your UniFi account are automatically added to the Organization.
- If there are sites you do not want included, transfer their ownership before creating your Organization.
- If a site is accidentally added, you can remove it afterward by transferring ownership.
-
Go to neworg.ui.com
- You’ll be guided through creating your Organization, including:
- Adding admins
- Reviewing and confirming included sites
- Assigning roles and permissions
- (Optional) Setting custom domains and logos
- You’ll be guided through creating your Organization, including:
-
(Optional) Configure Identity Hub
- Identity Hub enables centralized user management, SAML-based SSO, and permission assignment for services like:
- UniFi Door Access
- One-Click VPN
- One-Click WiFi
- For setup instructions and Identity Provider integration, see: Creating an Identity Hub For Your Organization.
- Identity Hub enables centralized user management, SAML-based SSO, and permission assignment for services like:
-
Configure Organization Admins
- For steps to add and manage Organization and Site Admins, see Manage UniFi Organization Users and Admins.
-
Assign User Permissions and Onboard Them to the Identity Endpoint App
- The Identity Endpoint App enables users to securely access assigned services using their existing SSO credentials.
- Authentication is powered by your Identity Provider and includes support for MFA-based sign-in.
- For detailed steps, see: Managing Organization User Permissions and Identity Endpoint Onboarding.
Automatic migration isn’t ready yet, follow the steps below:
- Create a new Organization with a different domain.
- Use it to confirm that Organization Manager gives you all the features you need.
- Once you are confident that the Organization setup works for you:
- Deactivate the old Identity Enterprise workspace or change the Identity Enterprise domain in Identity Enterprise Manager > Settings > Workspace > Subdomain. (Note: You can skip this step if your Identity Enterprise workspace is deactivated)
- Submit a support ticket to request domain deletion.
- Once Support confirms the domain is free, go to Organization Manager > Settings > General > UI Workspace and assign that domain to your new Organization.
Data‑loss warning: Deleting the Enterprise domain permanently erases all Identity Enterprise data. Re‑enabling Enterprise later would require a full re‑setup.
For a detailed comparison between Organization Manager and Identity Enterprise Workspace, please refer to Feature Comparison: UniFi Identity vs. UniFi Identity Hub vs. UniFi Identity Enterprise.
Organization and Identity Hub Management
For more information, see Managing Your UniFi Organization.