Ubiquiti unifi network integration to be broken by change to MFA

I use the Ubiquiti unifi network integration to turn off and on devices on my network.
Over the next month Ubiquiti is going enforce mandatory MFA logins that is going to break the Unifi integration.

I wanted to find out what other options there is and also how many people in our HA community will be impacted. I am suprised that Ubiquiti have not invetigated an API key to allow this to continue working as is has been a great “feature” available to unifi users.

Breaking this functionality is enough to make to move my entire network to a different technology.

why ?

As i read there mails is UI accounts will be secured by MFA, not LOCAL account

1 Like

MFA does not affect the integration as @Michael_Dahl says. I’ve been running my Unifi with MFA for a lot of years (you should too).

3 Likes

I just activated MFA and within minutes my Verify App started asking for login confirmation multiple times. When checking the HA dashboard shortly after I got no info from the Unifi devices. When checking the integration the Unifi Network integration gave error “Failed to set up”

Please help??

Thanks for asking and thanks for the clarifying answers :slight_smile:

I had the same problem, but I solved it. To do this, I registered a new “administrator account” through the controller’s website.

  1. administrators
  2. all sites
  3. add new admin
  4. uncheck “remote access”
1 Like

Same issue here as well.

I’m using a Unifi Local Super Admin for credentials on Home Assistant. I can create and re-create the Unifi Network integration, no problem.

But when I do activities such as switching off/on Port Forwarding rules or switching off/on specific connected client, I get an authentication error on Home Assistant. And the switching function is non-functional.

I rolled back several version of Home Assistant and this error persists. So I has to do with the new Unifi OS version 4.0.6.

This integration is broken.

This works, as local account does not enable MFA (for now at least).

Anyone know how to change the email address on the admin account? I tried just about everything I could think of. I can’t even add a new user account - it gives me an error. I’m about to lose control of the email that it’s current using.

How does this integration interact with the unifi online system? It doesn’t seem like they communicate as the admin accounts are different in the integration and the online one.

It doesn’t.

Try reaching out to their support for the e-mail change.

That makes no sense if the integration doesnt interact w/ the online Unifi web app…
Where is the email address stored? I need to change it - I’m running out of time before I cant access the email its send the MFA to.

What are you actually trying to do? The local user account which you need to use the integration does not require an e-mail address.


I clicked around now and if you need to change your owner e-mail address (this has nothing to do with your integration) you can do that here https://account.ui.com/

1 Like

This… @jazzmonger You need to do that work on UI.com

The HA integration ONLY uses a local account and local access to the UniFi devices your email address is in your account on unifi

The HA integration ONLY uses a local account and local access to the UniFi devices your email address is in your account on unifi

I totally get that. But somehow the email address listed on the admin page of the unifiy app in HA is NOT the email address the MFA is sent to when I log in. I’ve changed/deleted the admin user in both the HA app and on the UI.com site to no avail…

I have NO idea where it’s grabbing this email address. Its not in HA:

I’ve been doing cisco CLI style networking for 45 years. Not my first rodeo, but this is driving me nuts…

I’m now at a complete loss. Delete and reinstall I suppose?

Jeff

That email is reported as the email address tagged to the account you’re using to connect with the device. That looks like what my old admin account looked like (it was a cloud account) I created a new local only account account according to the instructions, gave it admin (service acct) and the reconfigured to connect there. New local only accounts have no email. That tells me yours is older than that.

ok, got it. that worked. the trick was to create a new site admin and untick the “Remote” box.

1 Like