Does a former employee keep access for 30 days?
No. The 30 days are the convenience of not signing in again while the person is active. Once they are removed from the group or disabled in Entra ID, automatic reconciliation cuts their access within minutes — and an operator can revoke all of their devices at once from the console.
Do I need Active Directory, RADIUS or Windows Server?
No. The identity is the Microsoft Entra ID you already use. No domain controller, no NPS, no RADIUS.
Do I need a Microsoft 365 license for everyone who uses the Wi-Fi?
No. Sign-in uses Microsoft Entra ID, whose free edition comes with any Microsoft 365 or Azure subscription and includes sign-in to unlimited apps. Each person needs an account in your company's Entra ID and to be in the authorized group; no Microsoft 365 or Office license needs to be assigned to them.
Does MFA require Entra ID P1 or P2?
No. Entra ID's security defaults are free: when they are on, everyone registers for MFA with an authenticator app (such as Microsoft Authenticator), and Microsoft prompts for it when it judges a sign-in needs it. To require MFA on every sign-in, or to set your own rules, you need Conditional Access, which requires Entra ID P1, included in Microsoft 365 Business Premium, E3 and E5. The portal applies the rules your Entra enforces at sign-in and charges nothing extra for it. The exception is device-based rules (compliant or hybrid-joined device): a captive-portal browser cannot present the device, so exclude the portal's app from those policies.
What about guests: visitors and Entra guest accounts?
A visitor with no account in your company gets in with a voucher — no Microsoft sign-in, and not counted in your plan. A guest account (B2B, guest type) that you put in the authorized group gets in like an employee, signing in with their own company's account, and counts as a person in your plan. Microsoft bills guests by monthly active user; the first 50,000 are free.
Does it need a VPN, a public IP for RADIUS, or UDP?
No. Everything runs over HTTPS: the portal reaches your controller's API over HTTPS, and devices reach the portal over HTTPS. It works behind CGNAT and on satellite links.
What if the portal goes down?
People who are already signed in do not notice. The UniFi controller keeps devices authorized for 30 days; only new sign-ins and renewals wait until the portal is back.
Does Winserv see users' passwords?
No. Authentication happens at Microsoft; the portal only orchestrates the OIDC flow and receives a token. Passwords and MFA never pass through us.
Which access points and controllers are supported?
UniFi Network (Ubiquiti) only, tested on UniFi Network 10.0, 10.4 and 10.6 and on UniFi OS Server, with an open SSID and the captive portal. It does not work with other vendors' controllers. Your UniFi controller stays on your side, reached over HTTPS.