Skip to content
Residential: Build to rent

Build to rent: a personal WiFi key per household, staff on EAP-TLS, visitors on the portal

Managed WiFi as a building amenity, the way BTR operators run it: each household gets one xPSK key with its own VLAN or role, issued with the tenancy. The on-site team signs in on EAP-TLS, visitors use the portal, and the locks and sensors keep their own keys. One authentication log, on the access points you already own.

  • ~1 million residents on Purple
  • 60% fewer helpdesk tickets at move-in
  • 99.9% RADIUS uptime SLA
Illustration
Illustration: one xPSK SSID with a unique key per device, resident, tenant and contractor, each on its own VLAN and bandwidth limit, revocable on its own.
Book my design session

Who is on the build to rent network

Who connects in a build to rent apartment block, and where each one lands

Two key lifecycles on one SSID: the household's key follows the occupancy, and the keys for locks, thermostats and leak sensors follow the unit, so a move-out revokes one and never touches the other.

Who connects in a build to rent apartment block, and where each one lands
Who or what connectsNetworkAuthenticationPlacementWhat starts and ends access
Team members on personal phonesOpenPurple app onboarding, certificate installed, no MDMOnboarding lane, then the group VLANEnds with the directory account
Prospects and visitors in the leasing suite and loungesOpenCaptive portal sign-in, consent recorded (or SSO, social, SMS)Guest VLAN, client isolation onConsent recorded at sign-in, session expires on timeout
Concierge, building managers and operations staffSecureEAP-TLS, certificate from your MDM over SCEPVLAN by directory groupAccount disabled, and RADIUS CoA ends the session
Resident householdsxPSKIndividual key, MAC-bound (one key per household)A VLAN or role per household, with its own bandwidth limitIssued with the tenancy, revoked at move-out
Smart locks, thermostats and leak sensorsxPSKIndividual key, MAC-bound (bound to the device's MAC)A device VLAN per class, apart from resident VLANsStays on its key between one tenancy and the next, revoked when the device is swapped
Door entry panels, CCTV, EV chargers and lift controllersxPSKIndividual key, MAC-boundA building-systems VLAN, unreachable from residentsOne key per device, rotated or revoked alone
Maintenance and fit-out contractorsxPSKIndividual key, MAC-bound (time-limited, no MDM)A contractor VLAN and bandwidth limit per keyEnds on its end date

Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.

Build to rent: open, secure and xPSK

Three networks, each doing its own job

Identity decides the VLAN inside each network, so one SSID carries many groups.

Prospects, visitors and staff phones: portal and onboarding lane

The guest lane for anyone who is not a resident, and the BYOD onboarding lane for team members whose phones are not enrolled in MDM.

  • Leasing suite and lounge guests on the portal. Sign-in by SSO, Google, Apple, Facebook or SMS, with consent recorded for GDPR and CCPA and client isolation on. Under 15 minutes to add the splash URL and RADIUS to a controller.
  • Team phones with no MDM. Sign in once in the Purple app and a WiFi pass installs, on Windows, macOS, Linux, iOS and Android, then the phone lands on its group VLAN.
Illustration

Lifecycle

Two lifecycles on one SSID: the household's and the unit's

A household turns over every year or two. A smart lock does not. Keeping the two lifecycles separate is what stops a move-out becoming an outage.

Issue with the tenancy

Create the household's key when the tenancy is signed: from the console, in bulk from the move-in list when a block opens, or through the Purple API from your own lease system. Building devices are keyed once, at commissioning.

Illustration

Place each household on its own VLAN

RADIUS returns the VLAN, role or group policy, depending on your vendor, with a bandwidth limit per key. Your access points enforce it, and any shared rule, such as a concierge printer, lives on your gateway.

Illustration

Operate every block from one log

Every accept and reject carries its reason, by household, member of staff and device, across every block and streamed to Microsoft Sentinel, Splunk, Elastic or Datadog.

Illustration

Revoke the household, keep the unit

At move-out the household's key is withdrawn and its live session ended with RADIUS CoA on access points that support it. The unit's locks and sensors keep the keys that were never the resident's.

Illustration

One authentication log

One authentication log across every block you operate

Resident keys, staff certificates and building-device keys land in the same log, so a resident's "my WiFi is down" is a lookup on the key and not a site visit.

  • Which households have joined since move-in, and which keys have never authenticated.
  • Which locks, thermostats and leak sensors are authenticating at each block, and on which VLAN.
  • Why a device was rejected: a revoked key, an expired key or an unbound MAC address.
  • Whether a move-out's session ended when the key was withdrawn.
  • Which contractor keys are still live after the job's end date.
Illustration

Works with

Your directory, your MDM, your SIEM, your access points

Nothing is replaced. Purple Access sits on the systems your team already runs.

  • Identity providers

    Over SAML and SCIM. Group membership decides the VLAN.
    • Microsoft Entra ID
    • Okta
    • Google Workspace
  • Device management

    EAP-TLS certificates delivered over SCEP, with a compliance-gated join.
    • Microsoft Intune
    • Jamf Pro
    • JumpCloud
    • Kandji
    • Hexnode
    • Iru
    • Addigy
  • SIEM

    The authentication log, over webhook or syslog.
    • Microsoft Sentinel
    • Splunk
    • Elastic
    • Datadog
  • Access points

    Mixed estates are supported.
    • Cisco Meraki
    • HPE Aruba
    • Ruckus
    • Juniper Mist
    • Ubiquiti UniFi
    • Cambium
    • Extreme
    • Fortinet

Proof

Resident networks at scale

About 1 million students and residents run on Purple's community networks, and US university housing across 40 buildings saw 60% fewer helpdesk tickets at move-in.

~1M
students and residents on Purple community networks
60%
fewer helpdesk tickets at move-in, US university housing across 40 buildings
99.9%
cloud RADIUS uptime SLA, in your contract
99.999%
uptime, with a 99.9% cloud RADIUS SLA and multi-region failover

Add-on: Purple Shield

Add protective DNS with Purple Shield

Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.

Illustration

FAQ

Questions IT leads ask

Do we need new access points in our blocks?

No. Purple Access is a cloud overlay on the access points your blocks already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.

Is xPSK one SSID or one per household, tenant or device?

One SSID. Every key on it has its own VLAN, policy and bandwidth limit, returned by RADIUS at authentication, and there is no per-SSID key ceiling. Adding a key never adds a beacon.

Is xPSK the same as iPSK, PPSK, DPSK, MPSK or EasyPSK?

Yes. xPSK is our name for the capability each vendor ships under its own: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK. Purple runs all of them from one platform, on a mixed estate.

How can WiFi be live on move-in day with no broadband order?

Your building already has the bulk internet and the access points. The household's key is the only thing that is issued, from the console, in bulk from a list or through the Purple API, so there is nothing for the resident to order and nobody to send.

What exactly happens at move-out?

The household's key is revoked, its devices fail their next authentication and RADIUS CoA ends the live session on access points that support it. The unit's locks, thermostats and sensors authenticate on their own keys, so they stay up, and the next household gets a key of its own.

What does MAC binding do for phones with a private WiFi address?

It is strongest on fixed-MAC devices such as locks, thermostats, sensors and TVs. A phone with a private address presents one address per network, so the household key does its work on the VLAN and the log shows exactly what joined. Do not rely on MAC binding to survive a phone resetting its private address.

Book a demo: we issue and revoke a key on a live network

Bring one block's worth of devices: a resident's phone, a smart lock, a leak sensor and a concierge laptop. We issue each a key or a certificate, place it on its VLAN and revoke one live, on the access points you already run.

  1. Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
  2. We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
  3. You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.

Your design session

Your live key demo

A Purple network engineer runs the demo with you, on your kind of estate.