Reference Guide
...
Basic Configurations for Unifi...
Permit Zone for TACACS/RADIUS
permit zone feature for tacacs/radius devices restricts user access to specific ip addresses or subnets only users accessing the ip addresses or subnets defined from permit zone can connect to the tacacs/radius devices when this feature is activated access attempts from a different client ip will be denied additionally, you need to disable the direct access option in the user group to use this feature this ensures users can authenticate only from the specified ip/subnet range to configure permit zone navigate to policy > permit zone click the + add button enter the ip address or subnet and select the username , you need to disable the direct access option in the user group to use this feature