winserv · wifi corporate sign-in for UniFi (Ubiquiti) Wi-Fi

Identity governance for corporate Wi-Fi

An employee leaves the company.
Their network access leaves too.

Corporate Wi-Fi sign-in through Microsoft Entra ID (OIDC + MFA) — no on-prem Active Directory, no RADIUS, no NPS, no PKI. Employees sign in once and stay connected for 30 days; when they leave the group or the company, their network access is cut within minutes.

UniFi only. It works on top of a UniFi Controller (Ubiquiti) — that is where the portal authorizes devices. It does not work with other vendors' access points: if your Wi-Fi is not UniFi, this product is not for you.

To set it up yourself you need to be a Microsoft Entra ID administrator in your company, and your UniFi Controller must be reachable from the internet. See the requirements.

Runs on Winserv infrastructure · Microsoft authenticates, we only orchestrate

When someone leaves, their access leaves too

The difference is not the sign-in — it is the offboarding. The 30 days are a convenience for people who are still with you, not a grace period for people who left: every few minutes the portal reconciles the authorized group in Entra ID and cuts Wi-Fi for anyone who no longer belongs to it. On top of that, group membership is checked again at every renewal, and an operator can revoke a user from the console, which disconnects all of that person's devices at once. This is corporate identity governance, not guest marketing.

Why it is different

Real MFA and Conditional Access

Entra ID challenges the user: Microsoft Authenticator, Windows Hello, device compliance through Intune — your policies, unchanged. The portal only orchestrates the OIDC flow.

Sign in once · 30 days

While an employee is active, the device stays authorized for 30 days with silent renewal — sign in once and forget the portal. The window follows the employment: people who leave lose access in minutes, not in 30 days.

Nothing to run

A managed service: no server, no VPN and no UDP to open. The portal talks to your controller over HTTPS, and nothing else on your network changes.

How it works

  1. Connect. The device joins the open SSID and lands on the captive portal.
  2. Microsoft sign-in + MFA. Entra ID runs the challenge, with your Conditional Access policies.
  3. Authorize. The portal lets the device in on the UniFi controller (authorize-guest).
  4. 30 days while active. Silent renewal, no new sign-in. People who leave are cut within minutes, whatever the window. And if the portal goes down, people already connected stay connected: UniFi keeps the device table.

What it replaces

BeforeAfter
On-prem AD + NPS + RADIUSA managed service — nothing to install
Windows Server (licences + CALs)Nothing — it uses the Entra ID you already pay for
A VPN so branch offices reach the ADHTTPS over the internet
A certificate per device (PKI)Open SSID + captive portal with native MFA
Domain controller upkeepNothing — Microsoft runs the identity

Pricing

Winserv WiFi

US$ 69/month · 14-day trial

Up to 50 people with active access. Unlimited devices. No setup fee for self-service.

  • OIDC + MFA through Entra ID
  • Guest vouchers, self-hosted
  • Silent renewal (30 days)
  • Offboarding revocation
  • Pre-registration API (Intune)
  • 8×5 support, business hours in Brazil (UTC−3)

More than 50 people: up to 100 for US$ 99, up to 250 for US$ 249, up to 500 for US$ 499 a month. The trial starts on the 50 tier; if your team is larger, the tier is adjusted at the end of the trial from the count you see in your own console. Over 500, or many sites? Talk to Winserv.

Companies in Brazil are billed in reais — preços em português.

Frequently asked questions

Does a former employee keep access for 30 days?

No. The 30 days are the convenience of not signing in again while the person is active. Once they are removed from the group or disabled in Entra ID, automatic reconciliation cuts their access within minutes — and an operator can revoke all of their devices at once from the console.

Do I need Active Directory, RADIUS or Windows Server?

No. The identity is the Microsoft Entra ID you already use. No domain controller, no NPS, no RADIUS.

Does it need a VPN, a public IP for RADIUS, or UDP?

No. Everything runs over HTTPS: the portal reaches your controller's API over HTTPS, and devices reach the portal over HTTPS. It works behind CGNAT and on satellite links.

What if the portal goes down?

People who are already signed in do not notice. The UniFi controller keeps devices authorized for 30 days; only new sign-ins and renewals wait until the portal is back.

Does Winserv see users' passwords?

No. Authentication happens at Microsoft; the portal only orchestrates the OIDC flow and receives a token. Passwords and MFA never pass through us.

Which access points and controllers are supported?

UniFi Network (Ubiquiti) only, tested on UniFi Network 10.0, 10.4 and 10.6 and on UniFi OS Server, with an open SSID and the captive portal. It does not work with other vendors' controllers. Your UniFi controller stays on your side, reached over HTTPS.

Ready to take RADIUS out of the picture?

Create your portal yourself in a few minutes — or, if you would rather talk first, a 20-minute call to see whether it fits your controller.