Myth: UniFi Network Forces You Into the Cloud

UniFi Does Not Force You Into the Cloud (Anymore)

UniFi Network has always shipped a self-hosted controller

Since the UniFi line launched, Ubiquiti has offered UniFi Network controller software you download and run on your own hardware. Windows, macOS, Linux. Free. No Activation, No subscription.

It has never required a Ubiquiti SSO account to set up. You install it, hit the local web interface, create a local admin, adopt your devices, and you are done. That was true then and it is still true today, and Ubiquiti still publishes the guide for it.

The claim that UniFI forces cloud registration was never true of the software controller.

But It was true of that hardware line, for about two years.

The UniFi Dream Machine shipped in December 2019 and completing setup required a Ubiquiti SSO account. I talked about it in the review and I was one of the people complaining about it at the time.

During that time period you could still download the self-hosted controller and set it up with no account for their switches and their access points. But there was no way to adopt a UDM to the self hosted controller. Also, as many of you may recall I did not much care for any of the UniFi routers back then and it was not until January of 2025 when they released version 9 before their routers became much better.

When it changed for UniFi OS based devices

UniFi OS 1.11.0, released December 2021. From the release notes:

Allow to set up a console without an SSO account.

It was like that for two years and they fixed it.

What self-hosting looks like now

The standalone Network Application has been superseded by the UniFi OS Server, released in 2025, which runs the full UniFi OS platform. The setup wizard has a button to proceed without a UI account. No special workaround, just click.

What features do require the cloud?

  • Remote access through Site Manager. Optional.
  • Cloud backups. Optional, encrypted with your own password.
  • SD-WAN configuration is stored in the cloud, though the tunnels are WireGuard peer to peer and traffic does not transit Ubiquiti.
  • Teleport VPN may proxy through Ubiquiti when a gateway sits behind a firewall.
  • Push notifications and email relay through Ubiquiti

Note: You can still get notifications via SMTP without the cloud, but you have to provide the service.

Why the myth sticks around

First impressions: A lot of techs bought a UDM between 2019 and 2021, hit the setup wall, formed an opinion, and never went back to check. They are still repeating it five years later.

The naming: Cloud Key. Cloud Gateway. Cloud Console. Those are boxes that do local processing with the word cloud printed on them. If your marketing says cloud, do not act surprised when people believe you.

Some Final Thoughts

Don’t we complain about companies doing something we don’t like with the hope they will stop doing the thing we don’t like? I know it feels rare when they listen but let’s be happy when they do.

UniFi has also setup a Trust Center page to be clear about how they operate

Does this ACTUALLY work now?

For quite a while, its been a compliant that the “bring your own SMTP” didn’t work unless you had “Remote Management” enabled. On a post somewhere, some said if you enable remote management and then disable it, you’ll get some notifications, but not all. For example, IDS/IPS/Firewall notification never come through unless remote management is enabled but you can still get some stuff like console logins, updates waiting, etc…

SMTP has always worked with the stand alone, self-hosted Unifi Network. But, in my experience, doesn’t fully work otherwise.

1 Like

Tom, thanks for pointing out the “Cloud” naming stuff. I have been saying for years that it is a horrible idea for them to use that word in their products.

Of course, the naming of their products has always been kinda insane and confusing :slight_smile:

Regarding local SMTP for notifications, that still has some issues that could be major for some users… You can’t opt to use non encrypted SMTP sessions, period. But even worse, if you support encryption, it will refuse to use a SMTP server that uses a self-signed certificate, which is incredibly annoying. It used to be you could hack a setting in a config file, but I think that is gone now. Plus, for a while, recently, they completely broke local SMTP for certain notifications (I can’t remember which modules and circumstances at the moment, but it was when they moved the SMTP settings from Network into Console).