How-To: Connect Your Ubiquiti UniFi Network to Keytos Shield

Learn how to securely connect your Ubiquiti UniFi network to Keytos Shield using Cloud RADIUS.

Overview - How to Protect Your Ubiquiti UniFi Network with Cloud RADIUS

Having a single Wi-Fi password for your network is a security nightmare. It’s impossible to know who has access to your network, and it’s nearly impossible to change the password regularly without causing major outages. The best way to secure your Ubiquiti UniFi network is to use WPA-Enterprise with either certificates or individual user accounts for authentication.

To protect your Ubiquiti UniFi network using certificates or Entra ID accounts, you will need a RADIUS server to handle authentication requests. Keytos Shield includes a cloud-based RADIUS-as-a-Service that integrates directly with Entra ID to provide secure authentication for your Ubiquiti UniFi network without needing to manage any RADIUS servers or infrastructure. Simply add Keytos Shield as a RADIUS server in your Ubiquiti UniFi Controller, and your users can log in using either passwordless certificates or their Entra ID username and password.

Prerequisites for Setting Up Cloud RADIUS for Ubiquiti UniFi

The first step to getting started with Keytos Shield is to create a subscription. This will allow you to access the Keytos Shield portal and begin onboarding your users and devices.

How to Install Keytos Shield and Create a Subscription

It's free to get started and there's no sales call or credit card required

Keytos Shield uses native Entra ID authentication to provide a seamless passwordless experience for your users. Begin by registering the Keytos Shield Entra ID application using the link below. Make sure to use your Global Administrator account (or forward the link to your Global Administrator) to complete the consent process.

Single Click

The easiest way to register the applications is to click the button below while logged in with your Global Administrator account:

Register Keytos Applications

Manual URL

Alternately, you can copy & paste the following URL into your browser. Make sure you are logged in with your Global Administrator account before accessing the link.

https://login.microsoftonline.com/organizations/adminconsent?client_id=2963e596-88f5-43a1-ab17-68b8026c6468&redirect_uri=https://portal.keytos.io/Welcome

You will see a consent screen similar to the one below. Click Accept to register the applications in your tenant.

Keytos Shield uses native Entra ID authentication as shown in the admin consent screen

Single Click

The easiest way to register the applications is to click the button below while logged in with your Global Administrator account:

Register Keytos Applications

Manual URL

Alternately, you can copy & paste the following URL into your browser. Make sure you are logged in with your Global Administrator account before accessing the link.

https://login.microsoftonline.us/organizations/adminconsent?client_id=2cf07322-0273-4052-bd9b-e38c1c433803&redirect_uri=https://portal.keytos.us/Welcome
Keytos Shield uses native Entra ID authentication as shown in the admin consent screen

For more information on these specific permissions and why they are needed, please refer to the Keytos Shield FAQs.

Collapses this section and completes the checkmark.

How to Create Your Keytos Shield Subscription

A Keytos Shield subscription handles permissions, billing, and central configuration for your organization. You can create a subscription directly with us, or through the Azure Marketplace. Both options provide a 1-month free trial, and you can cancel at any time.

To create a Keytos Shield subscription directly through the Shield portal, follow these steps:

  1. Open the Keytos Shield portal in your browser. (US Government Portal).

  2. Under Subscription Name, enter a friendly name for your subscription. (you can always change this later)

  3. Select a Deployment Location for your subscription. This will be your primary region where your Keytos Shield resources will be hosted.

  4. Optionally enter your credit card information. You can click Skip for now if you just want to try out Keytos Shield for free for 1 month and add a payment method later.

    • If you are managed by a MSP or reseller, the credit card form will not be shown, and you can proceed with creating your subscription without entering any payment information.
  5. Check the Terms & Conditions box to agree to the terms of service.

  6. Click Register to create your subscription. It should complete in just a few seconds.

    Get started with a Keytos Shield free trial subscription
  7. You should now see your newly created Keytos Shield subscription endpoint listed under Existing subscriptions:

    Keytos Global Get Endpoint in Existing Subscriptions

We are finishing up our Azure Marketplace review with Microsoft and will have our documentation available soon. In the meantime, please deploy your Keytos Shield subscription directly through the Shield portal.

Collapses this section and completes the checkmark.

Now that you have created a Keytos Shield subscription, you can proceed to onboard your environment to Shield using the onboarding guide.

How to Configure Shield via the Onboarding Guide

The Shield onboarding guide will walk you through the steps to onboard your environment to Shield

It’s easy to get started with the interactive onboarding guide within Keytos Shield. Follow these steps to onboard your environment and configure your network security settings.

  1. Open the Keytos Shield global portal in your browser. (US Government Portal). Make sure to sign in with the same account used to create your Keytos Shield subscription.

  2. Under Existing subscriptions you’ll see your region-specific Keytos Shield endpoint. Open it to access the onboarding guide and start configuring your network security settings.

    Keytos Global Get Endpoint
  3. You should automatically be redirected to the network security onboarding guide on first login. If not, you can manually navigate to it from the left-hand nav bar under Onboarding:

    Onboarding Section

Collapses this section and completes the checkmark.

How To Register the Keytos Entra ID Application (already completed)

Since you have already completed this earlier, the step should be marked as completed. If there was an issue with the consent, refer to Step 1 above to re-consent the application using your global administrator account.

Register the Keytos Entra ID Application

Collapses this section and completes the checkmark.

How To Configure Your Infrastructure and PKI Environment

In step 2, you’ll answer a few questions about your environment and how you want to configure your PKI and MDM settings.

How to Set Up Your PKI in Keytos Shield

Keytos Shield includes a Cloud PKI which will issue your SCEP certificates. If you only have cloud resources and no on-premises PKI, you can rely solely on the Cloud PKI for certificate issuance. If you have an existing on-premises PKI, you can integrate it with Keytos Shield to chain your Shield SCEP CA up to your existing Root CA.

  1. What type of environment do you have?

    • Select Hybrid infrastructure if you have an on-premises Active Directory environment and/or an existing PKI environment that you want to integrate with Keytos Shield.

    • Select Cloud only if you have a cloud-only environment and do not have an on-premises Active Directory or PKI infrastructure. You won’t be asked any further questions about on-premises PKI integration.

      Select Environment Type
  2. Will you use Windows Hello for Business for on-premises resources?

    • Select Yes if you have a hybrid environment and want to use Windows Hello for Business and certificates issued by Keytos Shield to authenticate to your on-premises resources.

    • Select No if you do not plan to use Windows Hello for Business for your on-premises resources.

      Windows Hello for Business
  3. Do you have an existing on-premises PKI?

    • Select Yes if you have an existing on-premises PKI environment and want to integrate it with Keytos Shield.

    • Select No if you do not have an existing on-premises PKI environment or do not want to integrate it with Keytos Shield.

      Existing PKI
  4. Will you use your existing Root CA as your Root CA?

    • Select Yes if you have an existing Root CA and want the certificates issued by Keytos Shield to chain up to it.

    • Select No if you want to use Shield’s Root CA instead of chaining up to your existing Root CA.

      Chain to Root CA
  5. Bring your own Root CA - If you selected Yes to the previous question, follow these steps to bring your own Root CA:

    1. Download the CSR from Keytos Shield.
    2. Submit the CSR to your existing Root CA to generate a certificate.
    3. Once you have the certificate, upload it to Keytos Shield, along with the Root CA certificate.
    Chain to On-Prem Root CA
  6. Which MDMs do you use to manage your devices?

    • Select any Mobile Device Management (MDM) solutions that you use to manage your devices. This will help Keytos Shield configure your SCEP CA correctly to be able to issue certificates via your MDM. You can always add more MDMs later if needed from the Network profiles page.

      Select Your MDMs
  7. Mark as Complete

    • Click Mark as Complete to save your settings and continue to the next step.

Collapses this section and completes the checkmark.

How to Configure Your Shield Network Profile

A Shield network profile defines how your network connects to Shield via RADIUS and/or RadSec. In this step you’ll configure how you plan to connect your network to Keytos Shield.

How to Configure Your Network Profile Basics
  1. Under Network profile name, enter a friendly name for your network profile, such as “Office Network” or “Headquarters”.

    Network Profile Name
  2. Select if you want to use RADIUS or RadSec for network authentication.

How to Configure RADIUS or RadSec

Based on your choice of RADIUS or RadSec, you will need to follow the specific configuration steps for that authentication method. Use the tabs below to view the instructions for each option.

Classic RADIUS is a great option if you want a straightforward and widely supported method for network authentication and you plan to do certificate-based authentication or Entra ID username & password authentication.

  1. Under Add IP addresses, click My IP or manually enter the public IP address for your network that will be sending RADIUS requests to Keytos Shield.

  2. Click Add to save the IP address to your network profile.

  3. Repeat for all your public IP addresses, including any backup IP addresses you may have for redundancy.

    Enter Classic RADIUS IPs

While RadSec is more complex to configure than Classic RADIUS, it is compatible with dynamic IP addresses and offers better security for legacy authentication protocols like PAP, PEAP, and MS-CHAPv2 if you plan to use them on your network.

Note: Make sure your network equipment supports RadSec. If it does not, you will need to use Classic RADIUS instead, or run a local proxy within your network that protects your RADIUS traffic inside an encrypted tunnel (useful if you’re using unencrypted protocols like PAP or MS-CHAPv2).

  1. Under Authorized certificate authorities > Certificate source, select where the certificate authority for your RadSec connection is located. Some APs, such as Meraki, come pre-configured with their own certificate authorities, while others like Unifi require you to provide your own certificate authority.

    • Shield: Select this option if you want to use the certificate authority provided by Keytos Shield to issue RadSec certificates for your network.

    • EZCA: Select this option if you want to use an existing EZCA certificate authority for your RadSec certificates.

    • Local CA: Select this option if you want to use a 3rd party certificate authority for your RadSec certificates.

      Select RadSec Trusted Certificate Authority
  2. (optional) Authorized certificate thumbprints: If you want to trust individual RadSec certificates based on their thumbprints, expand this section and upload your self-signed or third-party certificates.

    Network Profile RadSec Trusted Certificate

Want to protect your legacy authentication protocols like PAP, PEAP, and MS-CHAPv2 but can’t use RadSec? Or want to increase availability + reduce latency for your authentication requests? Running a local server within your network can help achieve these goals.

Keytos Shield comes with a free local RADIUS/RadSec server that you can optionally run within your network to handle authentication requests locally, providing an additional layer of security and control over your network authentication.

To set up a local RADIUS server, first set up RADIUS or RadSec as your primary authentication here in the onboarding flow, and then visit our guide on adding a local Shield RADIUS server to complete the setup.

How to Configure Network Profile Assignment and Optional Settings

Now that you have configured RADIUS or RadSec, the final steps are to choose what users and/or devices will be assigned to this network profile and configure any optional settings.

  1. For Authentication type, select the appropriate option for your network.

    • Device: Select this option if you want to authenticate individual devices on your network.

    • User: Select this option if you want to authenticate users on your network.

      Authentication Certificate Type

    Note: Want to use both? Select your primary authentication type here and complete the onboarding guide, and you can add additional authentication types in the Network profiles page later.

  2. For Profile assignment, either keep Assign to all licenses users selected, or uncheck it and choose the Entra ID user(s) and/or group(s) that you want to assign this network profile to.

    Network Profile Assign Profile
  3. Optionally enable Enable MAC authentication bypass if you want devices to bypass authentication based on their MAC address.

    • If you have a small set of MAC addresses, manually enter them and click Add.

    • If you have a large set of MAC addresses, check the box for Bulk upload addresses and upload a CSV file containing the MAC addresses.

      Network Profile MAC Authentication Bypass
  4. Click Save RADIUS Server to save your network profile and proceed with the configuration.

Collapses this section and completes the checkmark.

How To Add Your Wi-Fi Networks

Now that you have configured your RADIUS server, the next step is to add your Wi-Fi networks to Keytos Shield.

  1. Enter your Wi-Fi network basics:

    • Wi-Fi network name (SSID) - Add your SSID name here. This is case sensitive, so make sure to enter it exactly as it is configured on your network.

    • Wi-Fi encryption - Select the encryption type that matches your Wi-Fi network configuration.

    • Hidden SSID - If your SSID is hidden, enable this option.

    • Connect automatically when in range - Choose if you want your device to connect automatically when in range or not.

      Wi-Fi Network Basics
  2. Select if you want to Enable Keytos Connect for BYOD devices. This allows BYOD devices to connect via the Keytos Connect app without the need for an MDM solution. If you centrally managing your devices via an MDM solution, you can leave this option disabled.

    • If enabled, you can select if all licensed users can connect to this network, or only specific users/groups.

      Enable Keytos Connect
  3. Click Save Wi-Fi network to save your Wi-Fi network configuration and continue to the next step.

Collapses this section and completes the checkmark.

Here is where you will connect your Ubiquiti UniFi to Keytos Shield. Follow the instructions below to complete the network connection process.

Collapses this section and completes the checkmark.

Step-by-Step Guide to Setting Up Cloud RADIUS for Ubiquiti UniFi

The following steps will guide you through the process of setting up Cloud RADIUS for your Ubiquiti UniFi network using Keytos Shield.

How to Add Keytos Shield as a RADIUS Server in Ubiquiti UniFi

Now that you have your Keytos Shield subscription and access policy set up, you can add Keytos Shield as a RADIUS server in your Ubiquiti UniFi Network Controller.

How to Add a Cloud RADIUS Server to Ubiquiti UniFi

  1. Navigate to your Ubiquiti UniFi Controller.

  2. Click on Network on the top menu.

    Ubiquiti UniFi Controller Network Settings
  3. From the left-hand menu select Settings.

    Ubiquiti UniFi Controller Settings
  4. From the left-hand menu select Networks

    Ubiquiti UniFi Controller Settings with Networks page highlighted
  5. Scroll down to the RADIUS Servers section and click Create New.

    How to Create New RADIUS Profile in Ubiquiti UniFi Controller
  6. In the Add RADIUS Server dialog, enter the following details for your RADIUS server:

    • Name: Enter something like Keytos Shield

    • RADIUS Assigned VLAN Support: Select what type of networks you want to use with Keytos Shield, wireless and/or wired.

    • Leave TLS unchecked as this guide is for Classic RADIUS authentication and not RadSec.

      Adding RADIUS Server in Ubiquiti UniFi Controller

How to Get Your RADIUS Server IP Addresses for Ubiquiti UniFi

The Keytos Shield RADIUS IP addresses are needed for your network controller to communicate with Keytos Shield. You can get them from the onboarding guide or from the network policies page.

If you’re currently going through the onboarding guide, you can find the Keytos Shield RADIUS IP addresses in step 5, Connect your network. Copy one IP from each region, starting with the closest to you.

Keytos Shield Network Policies with the RADIUS Server IP Addresses highlighted

If you’ve already gone through the onboarding guide previously, you can find the Keytos Shield RADIUS IP addresses directly from the network profiles page.

  1. Navigate to the Keytos Shield Network Policies page from the left-hand menu.

  2. At the top of the page, select the Settings tab.

    Keytos Shield Network Policies with the Settings tab highlighted
  3. Scroll down to the bottom of the page and expand the Network Equipment section.

  4. Copy one of the IP address from the region closest to your network controller (you’ll add the others later).

    Keytos Shield Network Policies with the RADIUS Server IP Addresses highlighted

How to Add RADIUS Server IP Addresses to Ubiquiti UniFi

Now that you have your first RADIUS Server IP address, you can add it to your Ubiquiti UniFi Controller.

  1. Update the IP Address field with the RADIUS Server IP address you copied earlier.

  2. Leave the Port as the default of 1812.

    How to Add RADIUS Server for Entra ID in Ubiquiti UniFi Controller

How to Get Your Keytos Shield Shared Secret for Ubiquiti UniFi RADIUS

When you added your public IP address to your Keytos Shield policy, a shared secret was automatically generated for you. This shared secret is used to authenticate your network controller (RADIUS client) to the Keytos Shield server.

In step 5, Connect your network, of the Keytos Shield network security onboarding guide the Keytos Shield shared secrets are listed for each IP. Reveal and copy the value from your IP address.

Keytos Shield Network Policies with the Classic RADIUS Shared secret highlighted
  1. In the Keytos Shield portal, navigate to the Keytos Shield Network Profiles page from the left-hand menu.

  2. At the top of the page, select the Settings tab.

    Keytos Shield Network Policies with the Settings tab highlighted
  3. Scroll down to the bottom of the page and expand the Network Equipment section.

  4. For your public IP addresses, click the Copy button under the Shared secret column.

    Keytos Shield Network Policies with the Classic RADIUS Shared secret highlighted

How to Add the Keytos Shield Shared Secret to Ubiquiti UniFi

Now that you have your Keytos Shield shared secret, you can add it to your Ubiquiti UniFi Controller.

  1. Back in the Ubiquiti UniFi Controller, set the Shared Secret to the shared secret that corresponds to your IP Address from Keytos Shield.

  2. Click Add to save this IP address.

    How to Add RADIUS Server for Entra ID in Ubiquiti UniFi Controller
  3. Make sure repeat these steps to add one IP address from each Keytos Shield region to ensure high availability for your RADIUS authentication.

How to Configure RADIUS Accounting in Ubiquiti UniFi

Accounting logs contain information about user sessions and can be useful for auditing and troubleshooting. You can optionally enable RADIUS Accounting in your Ubiquiti UniFi Controller to send accounting logs to Keytos Shield. From there Keytos Shield can forward the logs to your SIEM and make them available in Audit Logs.

  1. Check the Accounting Servers box to optionally send RADIUS Accounting logs to Keytos Shield.

  2. Use the default Port of 1813 for accounting.

  3. Use the same Shared Secret as the RADIUS Servers.

  4. Click Add to save your RADIUS accounting server.

    How to Setup Cloud RADIUS Accounting Profile in Ubiquiti UniFi Controller

How to Save Your RADIUS Configuration in Ubiquiti UniFi

Now that you’ve added the RADIUS servers and accounting (if desired), you can save your RADIUS configuration.

  1. Leave Interim Update Interval unchecked.

  2. Finally, click Add to save your RADIUS Server.

    How to Add RADIUS Server for Entra ID in Ubiquiti UniFi Controller
How to Assign the Ethernet Port Profile to Switch Ports in Ubiquiti UniFi
  1. From the left-hand menu, click Ports.

  2. Select the first port you want to configure for RADIUS authentication.

  3. Under Advanced switch to Manual mode.

  4. Click the Ethernet Port Profile box.

  5. From the port profile list, select the Ethernet Port Profile you created earlier.

  6. Click Apply Changes to save your configuration.

    How to Assign Ethernet Port Profile to Switch Ports in Ubiquiti UniFi
  7. Done!

How to Add a RADIUS Server to a Ubiquiti UniFi Network

Now that you have added Keytos Shield as a RADIUS server within your Ubiquiti UniFi Network Controller, you can add it to your network so that when users connect to that network, they will be authenticated via Keytos Shield.

How to Add RADIUS to a Ubiquiti UniFi Wi-Fi Network

  1. Navigate to the WiFi menu on the left.

    How to Add RADIUS Server for Entra ID in Ubiquiti UniFi WIFI Controller
  2. Click the Create New button (or edit an existing network).

    How to Add RADIUS Server for Entra ID in Ubiquiti UniFi WIFI Controller
  3. Enter the SSID for your network.

  4. Leave the password field empty.

  5. Select if you want a specific VLAN for this network.

  6. Under Advanced, select Manual.

    How to Add Entra ID Authentication in Ubiquiti UniFi WIFI Controller
  7. Scroll down to Security Protocol and select WPA3 Enterprise (if you have legacy devices or passwords Select “WPA2 Enterprise”).

  8. Under RADIUS Profile, select the profile you created earlier.

    How to Add Entra ID RADIUS Authentication in Ubiquiti UniFi WIFI Controller
  9. Click on Create or Apply Changes.

    How to Add Entra ID Authentication in Ubiquiti UniFi WIFI Controller
  10. Done!

How to Add a RADIUS Server to a Ubiquiti UniFi Wired Network

It’s easy to leverage your RADIUS server to authenticate users connecting to your Ubiquiti UniFi wired network using 802.1X authentication. Follow the steps below to enable RADIUS authentication on your Ubiquiti UniFi Switch(es).

How to Enable RADIUS Authentication in a Ubiquiti UniFi Switch
  1. In the left-hand menu, click UniFi Devices.

  2. Select your switch from the list of devices and click on the Settings gear icon.

  3. Under the Advanced tab, uncheck Global Switch Settings.

  4. Enable 802.1X Control.

  5. For RADIUS Profile, select the Keytos Shield profile you created earlier.

  6. Click Apply Changes to save your configuration.

    How to Enable RADIUS Authentication in Ubiquiti UniFi Switch
How to Create an Ethernet Port Profile for RADIUS Authentication in Ubiquiti UniFi

This step is only necessary if you want to create a reusable Ethernet Port Profile for RADIUS authentication. You can also enable 802.1X directly on individual switch ports without creating a port profile.

  1. From the UniFi Settings page, scroll down to the Ethernet Port Profiles section.

  2. Click on Create New.

    How to create a new Ethernet Port Profile in UniFi for Keytos Shield cloud RADIUS
  3. Fill out the following fields:

    • Name: Enter a name for your Ethernet Port Profile (e.g., Keytos Shield Authentication).

    • Tagged VLAN Management: Set to Block All unless you want to use a specific VLAN.

    • 802.1X Control: Set to Auto.

      New Ethernet Port Profile in UniFi for Keytos Shield cloud RADIUS
How to Assign the Ethernet Port Profile to Switch Ports in Ubiquiti UniFi
  1. From the left-hand menu, click Ports.

  2. Select the first port you want to configure for RADIUS authentication.

  3. Under Advanced switch to Manual mode.

  4. Click the Ethernet Port Profile box.

  5. From the port profile list, select the Ethernet Port Profile you created earlier.

  6. Click Apply Changes to save your configuration.

    How to Assign Ethernet Port Profile to Switch Ports in Ubiquiti UniFi
  7. Done!