Ubiquiti UniFi Identity SSO Error: How to Fix It
Medium 20-45 minutes Medium Severity
Verified June 2026
- Error Code
- Identity SSO error
- Brand
- Ubiquiti UniFi
- Product Type
- networking
- Severity
- Medium
- DIY Difficulty
- Medium
- Estimated Fix Time
- 20-45 minutes
Ad
Tools You'll Need
- Web browser
- Administrator access to UniFi Network Application
- Administrator access to identity provider
How to Fix Error Code Identity SSO error
-
Access UniFi Network Application
Ensure you have local admin credentials before proceeding, as SSO users cannot access the system during this issue. -
Check Identity Provider Status
-
Download New Metadata
-
Update UniFi SSO Configuration
-
Upload New Metadata
-
Configure Group Mapping
-
Test SSO Authentication
-
Verify Certificate Validity
Ad
When to Call a Professional
Contact a network administrator or IT professional if you don't have access to the identity provider admin console, if certificate management is handled by your IT department, or if the SSO integration involves complex custom configurations that require specialized knowledge.Frequently Asked Questions
Why did my UniFi SSO suddenly stop working?
SSO typically breaks due to expired certificates, changes in identity provider configuration, metadata updates, or network connectivity issues between UniFi and your identity provider. Check your identity provider for recent changes or certificate expirations.
Can I still access UniFi if SSO is broken?
Yes, you can still log in using local UniFi accounts if they were previously configured. Use the local admin credentials to access the system and fix the SSO configuration. If no local accounts exist, you may need to reset the system.
How often should I update SSO metadata?
Update SSO metadata whenever your identity provider notifies you of changes, when certificates are renewed (typically annually), or when making configuration changes. Some organizations update quarterly as a best practice.
What's the difference between SAML and OIDC for UniFi SSO?
SAML 2.0 uses XML-based metadata files and is common with enterprise identity providers like Active Directory Federation Services. OIDC uses JSON and is more common with cloud providers like Google and Azure AD. Both provide secure single sign-on functionality.
Do I lose user settings when reconfiguring SSO?
User accounts and their associated settings are typically preserved when reconfiguring SSO, as long as the username mapping remains consistent. However, users may need to log in again after the SSO configuration is updated.