Real MFA and Conditional Access
Entra ID challenges the user: Microsoft Authenticator, Windows Hello, device compliance through Intune — your policies, unchanged. The portal only orchestrates the OIDC flow.
Identity governance for corporate Wi-Fi
Corporate Wi-Fi sign-in through Microsoft Entra ID (OIDC + MFA) — no on-prem Active Directory, no RADIUS, no NPS, no PKI. Employees sign in once and stay connected for 30 days; when they leave the group or the company, their network access is cut within minutes.
UniFi only. It works on top of a UniFi Controller (Ubiquiti) — that is where the portal authorizes devices. It does not work with other vendors' access points: if your Wi-Fi is not UniFi, this product is not for you.
To set it up yourself you need to be a Microsoft Entra ID administrator in your company, and your UniFi Controller must be reachable from the internet. See the requirements.
Runs on Winserv infrastructure · Microsoft authenticates, we only orchestrate
The difference is not the sign-in — it is the offboarding. The 30 days are a convenience for people who are still with you, not a grace period for people who left: every few minutes the portal reconciles the authorized group in Entra ID and cuts Wi-Fi for anyone who no longer belongs to it. On top of that, group membership is checked again at every renewal, and an operator can revoke a user from the console, which disconnects all of that person's devices at once. This is corporate identity governance, not guest marketing.
Real MFA and Conditional Access
Entra ID challenges the user: Microsoft Authenticator, Windows Hello, device compliance through Intune — your policies, unchanged. The portal only orchestrates the OIDC flow.
Sign in once · 30 days
While an employee is active, the device stays authorized for 30 days with silent renewal — sign in once and forget the portal. The window follows the employment: people who leave lose access in minutes, not in 30 days.
Nothing to run
A managed service: no server, no VPN and no UDP to open. The portal talks to your controller over HTTPS, and nothing else on your network changes.
authorize-guest).| Before | After |
|---|---|
| On-prem AD + NPS + RADIUS | A managed service — nothing to install |
| Windows Server (licences + CALs) | Nothing — it uses the Entra ID you already pay for |
| A VPN so branch offices reach the AD | HTTPS over the internet |
| A certificate per device (PKI) | Open SSID + captive portal with native MFA |
| Domain controller upkeep | Nothing — Microsoft runs the identity |
Winserv WiFi
US$ 69/month · 14-day trial
Up to 50 people with active access. Unlimited devices. No setup fee for self-service.
More than 50 people: up to 100 for US$ 99, up to 250 for US$ 249, up to 500 for US$ 499 a month. The trial starts on the 50 tier; if your team is larger, the tier is adjusted at the end of the trial from the count you see in your own console. Over 500, or many sites? Talk to Winserv.
Companies in Brazil are billed in reais — preços em português.
No. The 30 days are the convenience of not signing in again while the person is active. Once they are removed from the group or disabled in Entra ID, automatic reconciliation cuts their access within minutes — and an operator can revoke all of their devices at once from the console.
No. The identity is the Microsoft Entra ID you already use. No domain controller, no NPS, no RADIUS.
No. Everything runs over HTTPS: the portal reaches your controller's API over HTTPS, and devices reach the portal over HTTPS. It works behind CGNAT and on satellite links.
People who are already signed in do not notice. The UniFi controller keeps devices authorized for 30 days; only new sign-ins and renewals wait until the portal is back.
No. Authentication happens at Microsoft; the portal only orchestrates the OIDC flow and receives a token. Passwords and MFA never pass through us.
UniFi Network (Ubiquiti) only, tested on UniFi Network 10.0, 10.4 and 10.6 and on UniFi OS Server, with an open SSID and the captive portal. It does not work with other vendors' controllers. Your UniFi controller stays on your side, reached over HTTPS.
Create your portal yourself in a few minutes — or, if you would rather talk first, a 20-minute call to see whether it fits your controller.