System architecture, SIP 2.0 connection review, lift-control interfaces and mobile-app provisioning for multi-dwelling-unit intercom and access-control deployments.

Multi-dwelling unit (MDU) access control is one of the most complex residential security deployments: dozens of access points, thousands of residents, multiple visitor flows, and the requirement to work reliably without IT staff on site. This guide covers the architectural decisions that determine whether an MDU system scales smoothly or becomes a maintenance burden.

1. Scale Tiers and Architecture Choices

ScaleUnitsRecommended Architecture
Small MDU10–100Single entrance panel, cloud SIP server, mobile app only — no dedicated server hardware required.
Medium MDU100–5001–4 entrance panels, on-premise or cloud SIP server, optional indoor monitors for premium units.
Large MDU500–2,000Multiple entrance panels, resilient local or hosted SIP route, building-management console and lift-control connection review.
Master-planned community2,000–9,999Distributed SIP route, compound entrance panels, guard-station and vehicle-gate connection review, and an operations portal scoped to the project.

2. Access Point Inventory

A complete MDU access control design must cover all entry points, not just the lobby:

  • Main entrance panel(s): Visitor video intercom, resident RFID/face recognition reader, delivery buzzer function
  • Basement / parking entrance: Vehicle LPR or RFID barrier control; pedestrian access reader
  • Stairwell doors: Floor-level RFID readers with anti-passback (one credential per entry/exit cycle)
  • Amenity areas: Gym, pool, rooftop — time-scheduled access via the same resident credential
  • Unit front doors: Smart lock (fingerprint + RFID + app) — optional for premium developments
  • Delivery / parcel room: RFID or PIN access for courier delivery, with notification to resident

3. SIP Server Sizing

For on-premise deployments, the SIP server handles all video call routing between entrance panels and resident devices. Sizing rules:

  • Concurrent calls: For most MDUs, peak concurrent intercom calls are 1–3% of units. A 500-unit building needs a server supporting 5–15 concurrent SIP sessions with video.
  • Hardware: A dedicated mini-PC (Intel N100 or equivalent, 8GB RAM, 128GB SSD) handles up to 500 units comfortably. For 500–2,000 units, use a 1U rack server with 16GB RAM.
  • PBX route: SIP 2.0 connection to Asterisk, 3CX or another PBX can be reviewed against the selected intercom, codecs, registration and server configuration.
  • Redundancy: For large MDUs, deploy a hot-standby SIP server with automatic failover. Intercom calls must not drop when the primary server reboots for updates.
For a hosted SIP route, measure call and door-release latency during the pilot. Record the selected Asterisk, 3CX or other PBX path, network conditions and acceptance threshold in the project brief.

4. Lift (Elevator) Connection Review

Lift control is a project requirement in some MDU designs. If a visitor call should trigger a floor-authorisation action, document the intercom, access-control panel, lift controller, safety boundary and acceptance owner before selecting hardware.

Connection methods to review

  • Dry contact relay: The entrance panel's relay output connects to the elevator controller's floor-enable input. Simple, universal, limited to one floor per relay.
  • RS-485 signal route: Review the documented signal, floor-authorisation method and controller requirements with the named lift equipment.
  • BMS interface: Where a building-management connection is required, confirm the documented interface, data direction and test method for the selected configuration.

Anti-Tailgating for Lifts

In high-security MDUs, install a turnstile or speed gate at the lift lobby base. The intercom system grants the turnstile pass simultaneously with the main door unlock, preventing unauthorized residents from following the visitor to upper floors.

5. Mobile App Provisioning at Scale

Provisioning 500+ residents with app credentials is a project in itself. Best practices:

  • Bulk import: Use the building management portal's CSV import for resident names, unit numbers, and email addresses. The system auto-generates SIP extension credentials and sends an invitation email/SMS to each resident.
  • QR code self-enroll: For move-in day, generate a QR code per unit that residents scan to self-provision their app without IT intervention. The QR encodes the SIP server address, extension, and initial password.
  • Multi-user per unit: Each unit should support 2–4 concurrent app users (both spouses, adult children). Configure the SIP dial plan to ring all users in the unit simultaneously (ring group).
  • Renewal on lease change: A property-management connection can be reviewed for credential revocation and re-provisioning; confirm the interface scope, permissions and failure handling.

6. Visitor Management for Large Developments

For master-planned communities and gated compounds with a guard booth:

  • Guard station monitor: Dedicated 21" touch monitor at the guard post displays all active intercom calls, visitor logs, and gate status. Guard can unlock any gate from the console.
  • Pre-authorized visitor code: Residents pre-register a 6-digit visitor PIN via the app. Visitor enters the PIN at the entrance panel — door opens without calling the resident.
  • LPR (License Plate Recognition): Vehicle gate camera reads the plate, cross-references against the resident vehicle register, and opens the gate automatically. Manual plate entry for guests via resident app or guard console.
  • Delivery management: A QR-code or credential connection can be reviewed for timed access at the delivery entrance, subject to the selected workflow and controller.
FAQ

Frequently Asked Questions: MDU Access Control Design

Large MDU access control design can follow a zoned architecture: perimeter (building entrance), vertical (lift/elevator floor access), and horizontal (corridor and unit door). For 500–5,000 units, size the SIP intercom server for the expected concurrent call load — often modelled at 1–3% of units calling simultaneously at peak. SIP 2.0 connection to an Asterisk, 3CX or other PBX can be reviewed against the selected server, firmware and network design; local or hosted deployment is a project decision. Lift and visitor-management connections should be specified through the named controller, credential workflow and acceptance test rather than assumed from a catalogue description.

The number of door stations depends on building entry points, not unit count. A single-entrance tower of 500 units needs one lobby door station; a podium development with multiple lobbies and parking entrances may need 4–8 door stations for the same unit count. Each door station is a separate SIP endpoint on the building's SIP server. For buildings with multiple wings or blocks sharing a common access control platform, each entrance requires its own door station with its own SIP extension — the SIP server routes calls to the correct resident extension regardless of which entrance the visitor uses. Specify door stations with apartment directory capacity matching your unit count: most models support 100–9,999 directory entries.

A lift connection can restrict elevator floor access by credential when the selected reader, access-control panel and lift controller expose a tested path. Review Wiegand, OSDP or RS-485 wiring, floor-authorisation logic, safety boundaries and failure behaviour with the named equipment. If a manufacturer interface is required, confirm the documented connection scope and commissioning owner; do not assume a shared interface removes project-specific work.

For MDU buildings above 500 units, digital pre-authorisation is one visitor-management route to evaluate alongside staffed or resident-call workflows. A project platform may issue a time-limited QR code or PIN, record the invitation and entry event, and connect to the entrance device after model and workflow review. Test the chosen path, offline behaviour, guard process and audit requirements before rollout; do not assume one visitor method fits every building.

Bulk provisioning at MDU move-in requires a platform that supports CSV import of resident data (name, unit number, phone number, move-in date) and automated credential distribution. The platform generates unique activation links or QR codes per unit, sent to residents via SMS or email — residents download the app and activate their credential without visiting the management office. For buildings with phased handover (floors or wings handed over at different dates), the platform must support activation scheduling tied to individual unit handover dates. Avoid platforms requiring manual credential creation per resident — at 1,000+ units, manual provisioning takes weeks and creates errors. Test the bulk provisioning flow with 50 test accounts before building launch.

Illustrative MDU planning patterns vary by entrance count, call load, resident workflow and site network. A 100-unit building may use one or two entrance stations and a local or hosted SIP route; a 1,000-unit project may need multiple entrances, lift and visitor-control connections, network segmentation and server resilience; a 5,000-unit development may need distributed service and a central operations view. Confirm the selected model, SIP 2.0 connection to the named Asterisk, 3CX or other PBX, NVR/VMS or controller path, and acceptance owner before final design.

Common MDU commissioning risks include an untested Wi-Fi or PoE path, changing device addresses, too few entrance stations, no documented offline fallback, an untested lift or controller connection, an undersized SIP server and missing network records. Review each item against the selected model, firmware, site and named connection endpoint before handover.

Planning an MDU Project?

Share your unit count, tower configuration, target country and required connection path — we'll prepare a project-specific architecture, model shortlist and written scope.

Request MDU System Design Apartments & MDU Solutions