Access control systems are no longer standalone devices running on their own isolated networks. Modern platforms like Verkada, PDK Prodatakey, and Genea are cloud-managed, IP-based systems that run on your enterprise network. This means your IT team needs to be involved from the very first planning meeting.
The Network Requirements
Cloud-based access control systems need:
- Reliable network connectivity: If the network goes down, people can't get in (or out). PoE switches with UPS backup are essential.
- Bandwidth: While access control doesn't use much bandwidth per door, it adds up across a large facility. Factor in video verification feeds from integrated cameras.
- VLAN segmentation: Access control devices should be on their own VLAN, isolated from general user traffic.
- Firewall rules: Cloud-managed systems need outbound HTTPS to their management platform. On-premise systems need inbound access for remote management.
Power over Ethernet (PoE) and Door Hardware Reality
Controllers, readers, and locks don’t all draw the same amount of power. When you stack PoE switches:
- Budget per-port and per-switch power budgets, not just port count
- Plan for future doors on the same IDF before you exhaust spare PoE headroom
- Long cable runs may require higher gauge cable or mid-span injectors—validate against vendor distance limits
Undersized PoE shows up as “random” offline doors after go-live, not during lab testing.
Security Treat Access Control Like IoT
Readers and panels are attractive lateral-movement targets:
- No inbound management from the internet to controllers unless architected with zero trust or VPN—prefer cloud outbound or secure tunnels per vendor guidance
- 802.1X or MACsec where supported for switch-to-device trust
- Firmware cadence: patch on a schedule tied to change windows, not “when something breaks”
Choosing the Right Platform
Each platform has its strengths:
- Verkada: Tightly integrated with their camera platform. Great for organizations that want a unified security dashboard. Cloud-native.
- PDK Prodatakey: Cloud-based with strong mobile credential support. Good for multi-site management.
- Axis: Enterprise-grade with deep integration capabilities. Works well in complex environments.
- Ubiquiti UniFi Access: Cost-effective for smaller deployments, integrates with the broader UniFi ecosystem.
- Genea: Cloud-based with excellent visitor management and integration with workplace management tools.
Integration with Other Systems
Modern access control doesn't exist in isolation. Consider integration with:
- Surveillance cameras (event-triggered recording)
- Alarm systems (intrusion detection)
- HR systems (automatic provisioning/deprovisioning)
- Visitor management
- Building management systems (HVAC, lighting)
Identity: Beyond Badges
Enterprise deployments increasingly tie physical access to IT identity:
- SCIM provisioning from your IdP into the access platform where supported
- Role-based access aligned with HR status (joiner/mover/leaver)
- Visitor and contractor workflows with expiring credentials—reduces orphaned cards and PINs
Resilience and Fail-Open vs Fail-Secure
Doors fail open or secure based on code, safety, and policy—not vendor defaults alone. Network design should align with life-safety expectations: battery-backed strikes, mechanical override plans, and clear runbooks for extended outages.
A Practical Onboarding Sequence for IT
- Design VLANs, DHCP scopes, and firewall egress before hardware ships
- Label switch ports to panels in the same naming convention as your IPAM
- Pilot a single building with full monitoring (SNMP, syslog) before multi-site rollout
- Document certificate expirations for cloud connectors and API keys
The IT-Security Convergence
The days of physical security being managed entirely by a facilities team are over. Modern access control is an IT system that happens to control door locks. Organizations that recognize this convergence and involve their IT and network teams early in the process achieve better outcomes: more secure, more reliable, more integrated.