Airports: passengers on the portal, staff on EAP-TLS, airlines, handlers and concessions on personal WiFi keys
One terminal, many employers. Each organisation lands on its own role and VLAN over shared access points, scanners and gate readers get MAC-bound keys with no certificate to renew, and passengers use the portal.
- Vancouver International Airport
- Kinetic Melbourne Airport
- 80,000+ venues in 90 countries
- 99.9% RADIUS uptime SLA
Who is on the airports network
Who is on the terminal network, and the lane each one gets
Airlines, handlers, concessions and agencies share one terminal's access points and nothing else: a role and VLAN per organisation, keys for scanners and kiosks, passengers on the portal.
| Who or what connects | Network | Authentication | Placement | What starts and ends access |
|---|---|---|---|---|
| Passengers | Open | Captive portal sign-in, consent recorded (or SSO, social, SMS) | Guest VLAN, client isolation on | Consent recorded at sign-in, session ends at the timeout you set |
| Returning passengers and crew | Secure | Passpoint or OpenRoaming profile | Guest VLAN, with no portal on return | Profile installed once, valid at every site that runs it |
| Operator, airline, ground-handler and agency staff | Secure | EAP-TLS, certificate from your MDM over SCEP (each organisation's own MDM and directory) | A role and VLAN per organisation | Ends when the employer disables the account, or the contract ends |
| Seasonal, agency and contractor staff | xPSK | Individual key, MAC-bound (issued in bulk, no MDM) | The employer's VLAN, with a bandwidth limit per key | Ends on the date set, at season end or contract end |
| Retail and food concession staff and tills | xPSK | Individual key, MAC-bound | A key set and VLAN per concession | Revoked when the lease ends, one concession at a time |
| Scanners, check-in kiosks, gate readers and common-use check-in kit | xPSK | Individual key, MAC-bound | A locked-down device VLAN per class | One key per device, revoked when it is swapped |
Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.
Airports: open, secure and xPSK
Three networks, each doing its own job
Identity decides the VLAN inside each network, so one SSID carries many groups.
Passengers and staff phones: portal and onboarding lane
The public lane. Sign-in is a branded portal per terminal, and staff who bring their own phone onboard through the same lane.
- Passengers on the portal. SSO, Google, Apple, Facebook or SMS, with consent recorded for GDPR and CCPA, and under 15 minutes to add the splash URL and RADIUS to a controller. Returning passengers roam on a Passpoint profile with no portal.
- Staff on personal phones, no MDM. Sign in once in the Purple app and a WiFi pass installs on Windows, macOS, Linux, iOS and Android, so a handler's own phone never touches an MDM.
Employers and agencies: EAP-TLS, one role per organisation
One WPA-Enterprise SSID for every managed device. Cloud RADIUS checks each organisation's own directory and returns that organisation's VLAN or role.
- EAP-TLS from each employer's MDM. Microsoft Intune, Jamf Pro, JumpCloud, Kandji, Hexnode, Iru and Addigy deliver the certificate over SCEP. Each organisation runs its own, so the airport never holds another company's devices.
- A role per organisation, from its own directory. Entra ID, Okta or Google Workspace over SAML and SCIM. An airline disables its own leaver once and the terminal stops authenticating them.
Scanners, concessions and seasonal staff: a key each
Anything with no 802.1X supplicant or certificate store, and every worker with nothing to install, gets a key on one SSID. MAC binding stops a key becoming a second shared password.
- Scanners, kiosks and gate readers. Each on a MAC-bound key and a locked-down VLAN, with no certificates to renew across a fleet that sits in cradles for months.
- A key set and VLAN per concession. tills, back-office PCs and staff devices apart from passengers and each other, live at Vancouver International and Kinetic Melbourne Airport.
- Seasonal and contractor staff in bulk. A roster of starters becomes a key each in one import, every key with an end date, so peak-season access ends without a ticket.
Lifecycle
Key lifecycle: onboard, place, operate, end
The same four moves serve a scanner and a seasonal starter, driven from lists you already keep: a roster and your device register.
Issue from a roster, in bulk
Import the starters list or the device register and each line becomes a key with an end date, bound to the device's MAC where there is one.
Place on the organisation's lane
RADIUS returns the organisation's VLAN, role or group policy, depending on your vendor, with a bandwidth limit per key. Your access points enforce it and your gateway holds shared-service rules.
Operate one log for the whole terminal
Every accept and reject carries the organisation, the method and the reason, so "whose device is this" is a query, and the log streams to your SIEM.
End one key, one worker or one lease
A swapped scanner loses its key alone, and a concession that leaves has its keys revoked with nobody else touched. RADIUS CoA ends live sessions on access points that support it.
One authentication log
One authentication log across every terminal and employer
Operator, airline, handler, concession and passenger traffic lands in one log, so who is on the network is a query and not a walk-round.
- Which organisation each device belongs to, and which VLAN it landed on.
- Which seasonal keys are still live after the season's end date.
- Which concession tills authenticated today, and which were rejected and why.
- Which scanners have not authenticated since the last shift.
Audit
Concession payments apart from the terminal: what each assessor tests
Each concession is its own merchant with its own assessor. Purple never touches card data, and segmentation gives each assessor that concession's VLAN map and log.
PCI DSS v4.0.1 Req 2.3.2
Wireless keys must change when anyone who knows them leaves. A key per device makes that one rotation, and never a whole concession's tills.PCI DSS Req 8 and 10
Every authentication is logged with the identity and the reason, and streamed to your SIEM as evidence.
Works with
Your directory, your MDM, your SIEM, your access points
Nothing is replaced. Purple Access sits on the systems your team already runs.
Identity providers
Over SAML and SCIM. Group membership decides the VLAN.- Microsoft Entra ID
- Okta
- Google Workspace
Device management
EAP-TLS certificates delivered over SCEP, with a compliance-gated join.- Microsoft Intune
- Jamf Pro
- JumpCloud
- Kandji
- Hexnode
- Iru
- Addigy
SIEM
The authentication log, over webhook or syslog.- Microsoft Sentinel
- Splunk
- Elastic
- Datadog
Access points
Mixed estates are supported.- Cisco Meraki
- HPE Aruba
- Ruckus
- Juniper Mist
- Ubiquiti UniFi
- Cambium
- Extreme
- Fortinet
Identity providers: setup and mappingDevice management: setup and mappingSIEM: setup and mappingHardware setup by vendor
Proof
Airports run on it
- Vancouver
- International Airport runs on Purple, concessions on their own keys
- Melbourne
- Kinetic Melbourne Airport runs on Purple, concessions on their own keys
- 80,000+
- venues run on Purple, in 90 countries
- 99.9%
- cloud RADIUS uptime SLA, in your contract
Add-on: Purple Shield
Add protective DNS with Purple Shield
Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.
FAQ
Questions IT leads ask
Do we need new access points in the terminal?
No. Purple Access is a cloud overlay on the access points your terminals already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.
How does a handheld scanner or gate reader with no supplicant get on?
To the device its key is an ordinary WPA2-Personal passphrase, so there is no supplicant, certificate or portal. The per-device key is held on the access point side under each vendor's name for it (Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK).
Does xPSK take our WiFi out of PCI scope?
Purple never touches payment card data. Each till and card machine sits on its own key and its own VLAN, apart from guests and staff, and every authentication is logged as evidence for PCI DSS Req 8 and 10. We hand your QSA the VLAN map and the authentication log to test against.
How are seasonal and contractor staff switched off at season end?
Each key is issued with an end date, so access stops on that day with no ticket. To end one early, revoke that key alone.
Book a demo: we issue and revoke a key on a live network
Bring a till, a scanner, a kiosk and a starter. We issue each a key or certificate, place it in its lane and revoke one live, on the access points you already run.
- Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
- We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
- You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.
Your design session
Your live key demo
A Purple network engineer runs the demo with you, on your kind of estate.