Join our Newsletter — 33% off our NHI Course
Home› FAQ› Cyber Security› What is the difference between a single-member UAG…
Cyber Security

What is the difference between a single-member UAG array view and a multi-member array view?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 29, 2026 Domain: Cyber Security

A single-member array view shows only the external site address and HTTPS port. A multi-member view adds the options needed for array networking, including whether to use integrated NLB, the virtual IP, and the IP mapping for each array member. The difference is driven by whether UAG is managing one server or an actual array.

Why the UAG View Changes When You Move from One Server to an Array

A single-member UAG view is intentionally minimal because there is no array coordination to configure. The moment UAG is managing multiple members, the interface has to expose the array-level networking choices that make the members behave as one service, rather than as unrelated servers.

That shift is practical, not cosmetic. A single deployment only needs the external endpoint details, while an array must also define how client traffic is distributed and how each member is addressed inside the array.

For practitioners, the key distinction is whether the configuration is describing one appliance or the shared networking model for several appliances. In array mode, the view has to represent the load-balancing and addressing relationships that keep the members reachable and consistent.

What Appears Only in the Multi-Member Array View

The multi-member view adds the settings that are only meaningful when there is more than one UAG member. That includes whether integrated NLB is used, the virtual IP that fronts the array, and the IP mapping for each member so the system knows where to send traffic.

Those fields exist because an array has two layers of identity, so to speak: the external address users connect to, and the internal addresses the individual members use to participate in the cluster. A single-member deployment collapses those layers into one server, so the extra array wiring is unnecessary.

This is why the two views are not just different presentations of the same data. The single-member view reflects a simple publish point, while the multi-member view reflects a coordinated traffic path and member mapping model.

What the Difference Means for Configuration and Troubleshooting

The configuration difference matters most when you are validating reachability. In single-member mode, you verify one external site address and port; in array mode, you also have to confirm that the virtual IP, the member mappings, and the chosen NLB approach all align with the intended traffic flow.

That makes the array view the one to use when diagnosing asymmetric access, member-specific reachability problems, or a mismatch between the published endpoint and the backend member addresses. If the array values are wrong, the external endpoint can look correct while traffic still fails behind it.

The practical takeaway is that the multi-member view is the operationally richer one because it exposes the dependencies that make a cluster work. If you are changing topology, adding a member, or reviewing failover behaviour, the array view is the one that reveals the real control points.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-05 — Identity Management, Authentication and Access ControlArray view differences affect how endpoints and members are reached.
Recommendation — Verify endpoint and member access paths match the intended topology.
NIST SP 800-53 Rev 5SC-7 — Boundary ProtectionThe array view exposes the external-to-internal traffic boundary.
Recommendation — Validate the virtual IP and traffic routing controls at the boundary.
ISO/IEC 27001:2022A.8.20 — Network securitySingle versus multi-member views change network configuration and routing assumptions.
Recommendation — Document and review the network path used by each deployment mode.

Practitioner Guidance

What to verify: Confirm whether the deployment is truly a single server or an array before interpreting the screen, because the presence or absence of array fields is driven by topology, not by a licensing or UI preference.

Decision rule: If there is only one member, treat the view as endpoint configuration only; if there are multiple members, validate the virtual IP, member IP mapping, and NLB choice together rather than as separate settings.

Common mistake: Teams often edit the external address and assume the backend path is automatically correct. In array mode, the internal mapping is part of the service definition, so you have to check the whole path, not just the front door.

Practitioner takeaway: The single-member view tells you how one UAG instance is published, while the multi-member view tells you how the array is built and routed, and that distinction becomes operationally important the moment traffic must be shared across members.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org