Where does UniFi top out in a 100-person office?
See where UniFi in an office hits airtime, controller, and gateway limits, how to load-test it, and when an enterprise platform makes sense.

UniFi can comfortably serve an office of 100 people if the network is designed around radio spectrum, traffic, and failures instead of the "up to 250 clients" figure on the box. Its ceiling rarely appears at employee number one hundred. Available airtime, sensible AP placement, gateway performance, or the administrator's tolerance for manual operations usually runs out first.
That is why asking whether UniFi can handle the load is almost meaningless without a floor plan. In one office, a hundred people use wired workstations and occasionally pick up a phone. In another, the same hundred people join video calls at once, walk between meeting rooms, print over Wi-Fi, and connect personal devices. The headcount is identical, but the load differs several times over.
This analysis avoids marketing arithmetic. The result should not be faith in a brand but a testable model: how many clients are truly active, how much airtime they consume, which node limits the network, and which failure the business is prepared to tolerate.
One hundred people do not mean one hundred Wi-Fi clients
Capacity planning must count devices and concurrent activity, not employee badges. One person may have a laptop and a phone, while a meeting-room panel, printer, television, and sensor also contain radios. Some devices stay connected while transmitting almost nothing. Others create short bursts that coincide when meetings begin.
Inventory the devices in four groups:
- work laptops and tablets;
- employee phones and guest devices;
- shared devices, including panels, printers, and media players;
- low-rate equipment, including old scanners and IoT devices.
For each group, record the quantity, supported bands, typical traffic, and location of concentration. Do not replace this table with a "three devices per person" multiplier. A multiplier works for an early budget, but it will not reveal that forty-five laptops gather in one meeting room while an old printer holds a low basic rate on 2.4 GHz.
There is another useful boundary: an associated client and an active client are different things. The first maintains a connection to an AP. At a given moment, the second occupies the channel with transmissions, acknowledgements, retries, and management frames. The controller may show 70 connections to one AP, yet a few active video streams and one weak client by the far wall will determine the experience.
I begin a design with a room table. It includes area, wall materials, expected occupancy, the share of wired desks, concurrent calls, and required applications. This quickly exposes two networks within the same office: a quiet desk area and dense meeting rooms. Averaging them together does not work.
Finally, separate availability from speed. A corporate messenger will tolerate a brief delay, while voice and a virtual desktop immediately expose jitter and packet loss. "Wi-Fi must work" defines nothing. "A video call must remain intact while moving from an office to a meeting room" can be tested.
An AP data-sheet limit does not define usable capacity
The maximum client figure describes how many associations an AP can maintain, but it does not promise acceptable service to every client. Ubiquiti's technical specifications list 250+ clients for U6 Pro and 500+ for U7 Pro Max. I would not design an office by dividing those numbers by the employee count.
One radio serves a shared channel in turns. A client with a weak signal takes longer to transmit a frame, a retry occupies the channel again, and a wider channel leaves fewer non-overlapping options for neighboring APs. A hundred devices exchanging occasional messages impose less load than twenty laptops on two-way video.
Three different ceilings matter:
- The association limit describes how many devices an AP can keep connected.
- The airtime limit arrives when there is no room left to transmit even though clients still connect.
- The application limit comes earlier or later according to acceptable latency, loss, and throughput.
The second limit causes most failures in a dense office. In UniFi Network, look beyond client count and aggregate traffic. Compare airtime utilization, retries, interference, RSSI, and client distribution across bands. High airtime with low outside noise points toward local contention or excess multicast. High airtime and interference together more often call for a different channel plan.
The advertised coverage area does not replace a survey either. Metal in a wall, cabinets, coated glass partitions, and people all change propagation. An AP may remain visible through three rooms while the two-way link is already poor: the laptop hears the powerful AP, but the AP struggles to hear the laptop's weaker transmitter.
U7 Pro Max has eight spatial streams, a 4x4 radio on 5 GHz, and a 2.5 GbE port. That provides more headroom than an entry-level AP, but it does not turn one channel into several independent channels. If you put a powerful AP in the middle of a floor and raise its power, edge clients will cling to it longer. You get a large but slow cell.
The controller and gateway limit different parts of the network
The controller manages configuration, telemetry collection, and device lifecycle, while the gateway routes and inspects production traffic. Confusing their limits is dangerous. A slow controller interface does not necessarily mean slow transfer between a client and a local server, but an overloaded gateway directly raises latency for internet traffic and inter-VLAN routing.
UniFi offers several control models: a Cloud Gateway combines UniFi Network and gateway functions, a CloudKey runs management applications without necessarily acting as the router, and UniFi Network Server can be self-hosted. In Ubiquiti's "Choosing the Right UniFi Control Plane" help article, UDM Pro, UDM SE, and UCG Ultra are placed in small and medium deployments, UDM Pro Max in medium and large deployments, and Enterprise Fortress Gateway is rated for 5,000+ clients. CloudKey Enterprise is described as a manager for large networks with support for up to 1,000 APs and switches. These classes help with selection, but the features enabled in a particular configuration change the available headroom.
Test the gateway with the features that will run in production. Firewalling, IDS/IPS, VPN, filtering, and inter-VLAN routing consume processor and memory resources. Gigabit port speed says nothing about how much traffic the device will process with the required inspections. Read the throughput specification with security features enabled, then retain headroom for updates and bursts.
When Network, Protect, Access, and other applications run on one console, they share compute and storage. A network with eight APs may be easy for Network, while camera recording changes console load. Ubiquiti explicitly suggests moving Protect and Access to dedicated consoles when more capacity is needed. That is more sensible than replacing every AP because the management page feels slow.
A self-hosted controller does not make Wi-Fi enterprise-grade by itself. It gives you freedom to choose the virtual machine and backup process, but you also own updates, certificates, the database, port access, and recovery. If nobody has restored a backup onto a clean system, the existence of a backup file does not count as a recovery plan.
For a 100-person office, I record four resources separately: managed device count, client count, gateway throughput with enabled features, and the load from other console applications. This makes the actual upgrade target visible. Higher-powered APs do not fix an overloaded VPN, and a new gateway does not repair overlapping radio channels.
Dense load exposes a bad radio plan
In a dense office, stability usually comes from more small, controlled cells, wired AP connections, and a careful channel plan. Trying to cover an entire floor with two APs at high power looks inexpensive only until the first company-wide meeting.
In its latency optimization guidance, Ubiquiti recommends medium transmit power, 20 MHz channels on 2.4 GHz, and 40 MHz channels on 5 GHz for dense environments. For an ordinary, less dense environment, it allows 80 MHz on 5 GHz. This difference matters more than the advertised peak speed: a 40 MHz channel offers a lower peak rate to one client but leaves more frequencies available for reuse by neighboring APs.
Do not set identical power everywhere without measurement. Clients have different antennas and make their own roaming decisions. Begin with medium power, measure cell edges, and reduce 2.4 GHz power where it travels farther than 5 GHz. The 2.4 GHz band is needed by old and distant devices, but it should not collect modern laptops from across the floor.
I treat a wired uplink for every production AP as standard. Mesh helps where a cable physically cannot be installed, but every wireless hop competes for the same airtime. Ubiquiti's dense-environment guidance says to minimize mesh and, when a wireless link is unavoidable, maintain a signal of at least -60 dBm between APs. A hundred-person office is not the place to turn a temporary cable substitute into the permanent design.
Minimum RSSI cannot be copied from somebody else's template either. The mechanism disconnects a weak client, after which the client chooses its next AP. If no neighboring AP is available, the device may reconnect to the original one and enter a disconnect loop. Ubiquiti's guidance says to derive the value from a survey and tune it per AP; its newer settings overview recommends Roaming Assistant as a gentler transition for modern clients, typically below -70 dBm.
Too many SSIDs consume airtime with management frames. A corporate network, a guest network, and a separate device network are usually enough if policy truly requires the separation. Do not create an SSID for every department merely to make the interface look organized. VLANs separate traffic without multiplying radio networks, while dynamic VLAN assignment through RADIUS lets you retain one corporate SSID.
Place APs around load zones instead of geometric centers in hallways. A forty-seat meeting room may need its own cell even though it covers less area than an empty lobby. Mounting above a metal duct or behind a suspended ceiling changes the radiation pattern, so every design on paper must be confirmed by measurements after installation.
A usable calculation starts with rooms and applications
For a typical 100-person office, begin with a testable hypothesis instead of a final AP count. Suppose there is an open area with 60 desks, two wings with 15 desks each, meeting rooms for 20 and 10 people, a kitchen, and several utility spaces. The inventory finds 230 registered Wi-Fi devices, 120 active during a normal hour, with activity shifting to the large meeting room during an all-hands session. This is a calculation example, not a universal norm.
The first hypothesis might use six wired dual-band APs: two in the open area, one in each wing, one by the large meeting room, and one serving the small meeting room and adjacent spaces. The average association count looks modest at about 38 per AP. But the average hides the important event: during a meeting, the large room's AP will have dozens of active clients, while neighboring APs hear it on the same channel.
Next, calculate the application. If 40 participants in one room each receive a 2 Mbps video stream, downstream payload alone reaches about 80 Mbps. Add upstream video, acknowledgements, management frames, retries, and other clients. You cannot distribute the PHY rate shown in the interface as useful throughput to everyone. It is the current radio link rate, not guaranteed application throughput.
Check the wired side of the same design. Six APs with 2.5 GbE ports require matching switch ports if you intend to use that headroom. The switch must supply the required PoE standard and enough total power for all APs at once. Its uplink, inter-VLAN routing, and the internet circuit also belong to the path. A gigabit uplink may be sufficient for actual production traffic, but measurement should establish that, not the shape of the AP connector.
After installation, run two surveys: one in an empty office and one under production load. The empty space exposes coverage and neighboring networks. People, open doors, full meeting rooms, and operating equipment reveal the real conditions. Measure more than signal strength. Capture latency to a local host, loss, retries, and throughput in both directions.
The result may call for five APs or eight. Six was a way to begin testing, not a promise. If the large meeting room creates a hot spot, adding an AP nearby without changing channels and power may make matters worse. A new AP helps when it creates a separate controlled cell and has a wired uplink.
Build a profile for the internet circuit instead of adding up device maximum speeds. Estimate video calls, cloud applications, backups, and large downloads separately. Then inspect the WAN queue during a peak. If latency rises when the circuit fills, queue management or a larger circuit will have more effect than replacing Wi-Fi.
Measurements must reproduce the user's complaint
A screenshot with a green client-experience score does not prove network quality. The on-call engineer needs a short test set that can be run in the problem location and compared with a known-good location. The test must separate the radio link, local network, DNS, and internet.
Place a wired iperf3 host in the same local network or a dedicated test VLAN. Run this on a laptop:
ping -c 100 10.20.0.1
ping -c 100 10.20.0.10
iperf3 -c 10.20.0.10 -t 30
iperf3 -c 10.20.0.10 -t 30 -R
The first ping checks the path to the gateway, and the second checks a wired test host. The two iperf3 runs test forward and reverse directions. In the final ping line, look for the form 100 packets transmitted, 100 received, 0% packet loss; for iperf3, compare the sender and receiver lines and their throughput. Values will vary by client and channel. The consistent procedure makes them useful.
During the test, record the AP, band, channel, width, RSSI, PHY rates, retries, and airtime. Repeat in three modes: empty office, normal work hour, and full meeting room. If local iperf3 is stable while the internet is slow, the radio is not the primary suspect. If latency to the local host jumps with retries, investigate the air.
For roaming, run a continuous ping to a local host and walk the usual route with the same laptop and an active voice call. Mark where the BSSID changes, how many replies are lost, and which AP the client selects. Repeat with a phone from another platform. The client makes the roaming decision, so one successful laptop does not prove behavior across the fleet.
In its WiFi Troubleshooting Guide, Ubiquiti recommends comparing airtime and interference. High airtime with low interference usually indicates local load or multicast. When both are high, inspect neighboring networks and matching channels. This classification is useful, but automatic channel changes still require manual verification after a production peak.
Write acceptance criteria before testing. They may include no loss across one hundred local replies in a normal area, a limited number of lost replies during roaming, a defined latency for the voice application, and minimum useful throughput in a full meeting room. The application owner chooses the values. Without them, the argument over whether Wi-Fi "works normally" never ends.
Security and operations may hit their limit before radio capacity
UniFi can segment networks, isolate clients, and use RADIUS, but the presence of settings does not replace an operating model. A 100-employee office must decide who grants access, how it is revoked, where identities live, what happens when RADIUS is unavailable, and who reviews changes.
A shared corporate SSID password is convenient until the first employee leaves or an unmanaged personal device appears. PPSK supports separate keys and VLANs on one SSID, but Ubiquiti's documentation explicitly limits this mode to WPA2, so it does not work on the 6 GHz band. RADIUS with WPA2 Enterprise or WPA3 Enterprise provides individual authentication and dynamic VLAN assignment, but adds a server, certificates, and a failure scenario.
The guest network must be isolated from production resources. Printers, panels, and IoT devices should not live in the user VLAN merely because discovery is easier there. Multicast and mDNS need deliberate rules: without them, devices cannot find one another, while overly broad forwarding consumes airtime and exposes unnecessary visibility between segments.
Restore the controller backup onto a clean system. Document the version, recovery order, local administrator credentials, and a path into the network when external connectivity fails. Automatic updates are convenient, but do not update every AP before an important event without staged testing. Keep a test group or a window in which a working version can be restored.
Enterprise class begins with failure and accountability requirements, not AP price. If the business requires two independent gateways with automatic failover, redundant power, multiple circuits, a contractual round-the-clock response, centralized NAC, and an auditable change history, compare those requirements with the exact architecture. Do not call a system inadequate when those needs do not apply. Simply acknowledge the boundary when they do.
There is an organizational ceiling too. One administrator may confidently operate one UniFi office, but dozens of sites with different versions, manual exceptions, and incomplete documentation create risk. If a change depends on one person's memory, radio performance is no longer the problem.
Wi-Fi 7 does not repair the architecture by itself
Moving to Wi-Fi 7 APs adds headroom only where clients, the wired network, and the frequency plan can use it. Replacing old APs one for one often preserves the same dead zones, overloaded cells, and poor positions. The specification changes, while the source of the complaint remains on the hallway ceiling.
Start with the client fleet. If most laptops support only 5 GHz with Wi-Fi 5 or Wi-Fi 6, a new AP's 6 GHz radio will not directly unload them. They will keep sharing the familiar band. An upgrade may make sense for lifecycle and future clients, but calculate the current effect from actual adapters, drivers, and applications.
The 6 GHz band provides more available spectrum and fewer legacy clients, but it penetrates obstacles less effectively. That suits a dense zone with modern equipment and nearby APs. It is a poor reason to cover several offices with one AP. Check the channels and transmit powers allowed in the country because the available set depends on local regulation.
A 320 MHz width looks impressive in the U7 Pro Max specifications, yet a dense office does not always need the maximum width. A wide channel helps a compatible client reach high speed in clean spectrum. If neighboring APs hear each other or the available band is restricted, a narrower channel may give the whole network more predictable service. Select width after measurement, not merely because the new generation supports it.
The wired side must match the upgrade goal. A 2.5 GbE AP port needs the same switch port, appropriate cabling, and enough uplink capacity farther along the path. The AP also needs the specified PoE class and total switch power budget. Connecting it at one gigabit is not necessarily a problem because actual production traffic may stay below that rate. But then the purchase cannot be justified by speed the path cannot physically carry.
Test the upgrade in the hardest zone:
- Record baseline measurements on the old AP during a production peak.
- Put the new AP in the planned position with the correct wired uplink.
- Repeat the test with the same laptops, phones, and applications.
- Compare latency, loss, retries, airtime, roaming, and switch load.
- Repeat separately with an old client that will remain in service.
If improvement appears only on one new laptop next to the AP, the project has not yet proved value to the office. If retries fall in the dense meeting room, more clean channels become available, and new clients move reliably to 6 GHz, the upgrade addresses a measured need.
Do not confuse a standards upgrade with a move to an enterprise platform. Wi-Fi 7 describes radio technology, while enterprise requirements include redundancy, authentication, logs, roles, support, and change control. A poorly managed network can use the newest APs. A Wi-Fi 6 network can also remain stable when capacity is sufficient and the team controls failures.
A mixed fleet can be practical. Put new APs in dense areas and locations where clients and switches have already been upgraded. Leave functional older APs in low-load spaces if one controller version supports both models and the update policy is clear. The budget then follows load instead of the urge to replace every device at once.
Before purchasing, verify each model's support lifetime and compatibility with the required UniFi Network version. A new controller release may drop old hardware, while an old release may reject a new AP. This is a lifecycle risk rather than radio performance. Include it in the budget together with test time, spare equipment, and a rollback path.
A new-generation AP is useful when it fills a specific deficit: it gives compatible clients another band, raises dense-cell capacity, supports the required authentication method, or removes an uplink constraint. If the deficit sits in WAN, RADIUS, cabling, or recovery procedures, fix that first. A radio should not pay for another component's fault.
Five signs that tuning will no longer solve the problem
A move to another enterprise solution is justified when measured requirements consistently fail after the design has been corrected. A one-off complaint in a distant room needs diagnosis. A repeatable failure at the planned load with a sound channel plan indicates an architectural limit.
Watch for five signs:
- the required density cannot be served without your own APs constantly competing for channels;
- the gateway cannot sustain required throughput with security features enabled and enough headroom;
- a mandatory failure scenario cannot be implemented or tested regularly;
- operations lacks the required logs, roles, access integration, or fleet management;
- the vendor or integrator cannot provide the required support model and response time.
The first sign must be proven by a survey. If APs sit in the hallway, run at maximum power, and use 80 MHz channels, that is a bad design rather than a platform ceiling. First move APs toward clients, install cables, narrow the channels, and remove excess SSIDs. Then repeat the same load test.
The second issue often requires only a gateway replacement. APs and switches can remain if they meet requirements. A slow controller can likewise move to a more suitable console or server. A wholesale replacement is convenient for a supplier, but a customer needs it only when several layers have linked constraints.
The third and fourth issues rarely improve with another AP. If an audit requires individual access records, event export to the accepted system, role separation, and controlled changes, test each function in a pilot. A feature name in a comparison table does not show how it behaves when RADIUS fails, WAN disappears, or the controller updates.
Support matters when downtime has a price. A forum and a spare AP on a shelf do not suit every business. The customer should know who accepts an incident at night, who can access the configuration, how long replacement takes, and where the tested backup resides.
Requirements, not a badge, determine the decision
For a 100-person office, UniFi often remains a rational choice. Several wired APs, a careful radio plan, a suitable gateway, and clear operations can deliver the required result without an automatic change in equipment class. The system stops being economical when the team constantly compensates for an architectural gap with manual work or the business requires resilience and control that the selected configuration cannot provide.
Put the decision in a short table. Use rows for coverage, dense-zone capacity, roaming, protected gateway performance, segmentation, authentication, recovery, redundancy, logs, and support. In columns, record the requirement, test result, headroom, owner, and action on failure. A red status without a measurement is useless, and a green one without a test scenario is equally weak.
If the current network passes its tests, do not replace it because of fear around a round employee count. Fix the documentation, save a reference configuration, keep a spare AP, and repeat the survey after a floor-plan change or a noticeable shift in the device fleet. Growth from 80 to 100 people may change nothing, while a new thirty-seat meeting room can create a limit in one day.
If the tests fail, pilot two options in the hardest zone. Compare latency, loss, roaming, diagnostic time, recovery, and administrator labor instead of maximum PHY rate. Identical clients, the same application, and the same load hour produce a fair comparison.
As a system integrator, GSE.kz can build this assessment without tying it to one manufacturer, including the network and server layers, data-center requirements, and a round-the-clock support model. That makes sense when the customer needs one party responsible for the whole path instead of a separate box with a high specification.
The UniFi ceiling in a 100-person office is the requirement you can reproduce and the system can no longer meet after sound design. Until that test exists, a migration discussion remains an argument about brands. Once the test exists, the decision is usually obvious and much less expensive than guessing.
FAQ
How many UniFi APs does a 100-person office need?
There is no honest number without a floor plan. Six wired APs may be a good first hypothesis for a typical floor, but a dense meeting room or heavy walls can easily change the result after a survey.
Can one UniFi AP serve 100 clients?
Some models can maintain one hundred associations, but that does not mean acceptable service for one hundred active clients. Airtime, signal quality, and application behavior will run out before the data-sheet limit.
Which matters more in UniFi, the controller or the gateway?
They limit different parts of the system. The controller handles management and telemetry, while the gateway processes routing, VPN, and security, so gateway overload directly affects production traffic.
Will Wi-Fi keep working if the UniFi controller fails?
Already configured APs normally continue forwarding local traffic when a separate gateway, DHCP, and authentication remain available. Management, telemetry, the guest portal, or dependent services may stop, so test the scenario in your configuration.
What channel width suits a dense office?
A practical starting point is 20 MHz for 2.4 GHz and 40 MHz for 5 GHz. A wide channel gives one client an attractive peak speed but leaves fewer frequencies for neighboring APs.
Should Minimum RSSI be enabled on every AP?
No. One value applied without a survey often creates disconnect loops for weak clients. Tune the threshold for each cell and verify that a better neighboring AP is truly available at its edge.
Is UniFi mesh suitable for a permanent office network?
Mesh is useful where cable cannot be installed, but a wireless uplink consumes shared airtime and reduces headroom. For one hundred employees, a wired connection to every production AP should be standard.
When does UDM Pro become a bottleneck?
It becomes a bottleneck when the gateway cannot sustain measured peak load with the actual IDS/IPS, VPN, filtering, and inter-VLAN routing enabled. Evaluate latency and CPU load in the production profile, not just port speed.
Is a shared Wi-Fi password safe?
It can be acceptable for a guest or restricted network when changed regularly, but it is poorly controlled for permanent employee access. Individual RADIUS authentication ties access to a person and makes revocation easier.
When should an organization move away from UniFi?
Move when the network still fails an agreed density, failure, security, or support test after a proper survey and tuning. Migrating because of employee count alone often means an expensive replacement of working equipment.