Getting Started with UniFi Fabrics
UniFi Fabrics provide a scalable foundation for managing multiple UniFi sites under a shared trust domain. By grouping sites into a fabric, you can centralize people and identity management, bind an Identity Provider (IdP) for zero-trust network security, and take advantage of advanced capabilities such as policy orchestration, centralized API endpoints, and device templates.
For more information, see here.
|
|
Getting Started
Best Practices
We recommend creating one Fabric per trust domain, typically defined by having a distinct Identity Provider (IdP) integration. While each Fabric currently supports a single IdP, future enhancements are planned to better support multi-tenant MSP scenarios. These enhancements will allow MSPs to use a single IdP for internal administrative access across all Fabrics, while also supporting customer-specific IdPs for user services (WiFi, VPN, Door Access) and co-managed administrative permissions.
Before creating a Fabric, we strongly recommend transferring ownership of all sites you intend to centralize to a single, company-owned email address (for example, it@example.com). Use this account to create and manage the Fabric. This approach helps ensure long-term continuity and prevents access issues during personnel changes.
Creating A Fabric
- Navigate to Site Manager.
- In the left-hand sidebar, open the Fabrics menu and click Create New.
- Enter a name for the Fabric and optionally upload a logo.
- Select the sites you own that will be members of the Fabric.
- Click Create Fabric.
Adding Sites To A Fabric
The Fabric Owner can add any site they own to a Fabric by following these steps:
- Navigate to Site Manager.
- In the left-hand Fabrics menu, hover over the Fabric and click Configure.
- Click Add Sites.
- Select the sites to add.
- Confirm the changes.
Removing Sites From A Fabric
The Fabric Owner can remove sites from a Fabric as follows:
- Navigate to Site Manager.
- In the left-hand Fabrics menu, hover over the Fabric and click Configure.
- Click Remove Sites.
- Select the sites to remove.
- Click Remove Sites to confirm.
Identity & Consolidated People Management
By default, each UniFi site maintains its own independent database of users and administrators. Fabrics allow you to consolidate people management across sites, providing several key benefits:
- Manage all people, including their Door Access credentials, from a single, centralized location
- Assign roles and permissions consistently across sites
- Enable the Identity Endpoint app for seamless access to UniFi services, including WiFi, VPN, and Door Access
- Optionally integrate with an external IdP for real-time employee onboarding and off-boarding, and secure SAML-based authentication
Consolidated People Management
To enable Consolidated People Management:
- Go to Site Manager.
- Select a Fabric.
- Navigate to Settings > Identity.
- Enable Consolidated People Management.
- Optionally Bind an Identity Provider for Zero-Trust Networking, and automated employee onboarding and off-boarding.
Enabling this feature automatically activates the Identity Sync Service, which runs on a designated UniFi Console referred to as the Master Site. This console acts as the orchestrator for people and permissions across all sites in the Fabric.
Explore Other Fabrics Features
- Bind an Identity Provider for Zero-Trust Networking, and automated employee onboarding and off-boarding
- Create Roles & Assign People Permissions