Build to rent: a personal WiFi key per household, staff on EAP-TLS, visitors on the portal
Managed WiFi as a building amenity, the way BTR operators run it: each household gets one xPSK key with its own VLAN or role, issued with the tenancy. The on-site team signs in on EAP-TLS, visitors use the portal, and the locks and sensors keep their own keys. One authentication log, on the access points you already own.
- ~1 million residents on Purple
- 60% fewer helpdesk tickets at move-in
- 99.9% RADIUS uptime SLA
Who is on the build to rent network
Who connects in a build to rent apartment block, and where each one lands
Two key lifecycles on one SSID: the household's key follows the occupancy, and the keys for locks, thermostats and leak sensors follow the unit, so a move-out revokes one and never touches the other.
| Who or what connects | Network | Authentication | Placement | What starts and ends access |
|---|---|---|---|---|
| Team members on personal phones | Open | Purple app onboarding, certificate installed, no MDM | Onboarding lane, then the group VLAN | Ends with the directory account |
| Prospects and visitors in the leasing suite and lounges | Open | Captive portal sign-in, consent recorded (or SSO, social, SMS) | Guest VLAN, client isolation on | Consent recorded at sign-in, session expires on timeout |
| Concierge, building managers and operations staff | Secure | EAP-TLS, certificate from your MDM over SCEP | VLAN by directory group | Account disabled, and RADIUS CoA ends the session |
| Resident households | xPSK | Individual key, MAC-bound (one key per household) | A VLAN or role per household, with its own bandwidth limit | Issued with the tenancy, revoked at move-out |
| Smart locks, thermostats and leak sensors | xPSK | Individual key, MAC-bound (bound to the device's MAC) | A device VLAN per class, apart from resident VLANs | Stays on its key between one tenancy and the next, revoked when the device is swapped |
| Door entry panels, CCTV, EV chargers and lift controllers | xPSK | Individual key, MAC-bound | A building-systems VLAN, unreachable from residents | One key per device, rotated or revoked alone |
| Maintenance and fit-out contractors | xPSK | Individual key, MAC-bound (time-limited, no MDM) | A contractor VLAN and bandwidth limit per key | Ends on its end date |
Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.
Build to rent: open, secure and xPSK
Three networks, each doing its own job
Identity decides the VLAN inside each network, so one SSID carries many groups.
Prospects, visitors and staff phones: portal and onboarding lane
The guest lane for anyone who is not a resident, and the BYOD onboarding lane for team members whose phones are not enrolled in MDM.
- Leasing suite and lounge guests on the portal. Sign-in by SSO, Google, Apple, Facebook or SMS, with consent recorded for GDPR and CCPA and client isolation on. Under 15 minutes to add the splash URL and RADIUS to a controller.
- Team phones with no MDM. Sign in once in the Purple app and a WiFi pass installs, on Windows, macOS, Linux, iOS and Android, then the phone lands on its group VLAN.
The on-site team: EAP-TLS and directory groups
One WPA-Enterprise SSID per block. Cloud RADIUS checks the directory and returns the VLAN for the group, so concierge, operations and head office each land in their own lane.
- EAP-TLS from your MDM. Microsoft Intune, Jamf Pro, JumpCloud, Kandji, Hexnode, Iru and Addigy deliver the certificate over SCEP, with a compliance-gated join. Setup is five to ten minutes, once, for the whole organisation.
- Directory groups decide the VLAN. Entra ID, Okta or Google Workspace over SAML and SCIM. Disable a leaver once and every block stops authenticating them.
- One directory group, every block. A concierge group lands on the concierge VLAN at every block, and a regional manager's group spans several, from one RADIUS and one directory.
Households and building devices: a key each, on its own VLAN
A resident's phone, a smart lock and a leak sensor have no common supplicant, so each gets its own key on one SSID. MAC binding stops a key becoming a second shared password.
- WiFi live on move-in day. The block's uplink and access points are already there, so the household's key is the only thing issued. There is no broadband order to place and no engineer to send.
- Move-out switches off one key. Revoke the household's key and its devices drop, with RADIUS CoA ending the live session. Every other household, and every device the building owns, stays connected.
- Locks, thermostats and leak sensors stay online between lets. Their keys belong to the unit and not to the resident, so an empty unit never takes its smart-home devices offline.
- Contractors with nothing to install. A time-limited key from the self-service portal or the Purple API, ending on the day the job does.
- A private network per flat. Each flat gets its own private network: their TV, speaker and console find each other, the neighbours' never appear.
- One key across the amenity spaces. Gym, lounge and roof terrace use the same key, so residents can still cast to their own devices.
Lifecycle
Two lifecycles on one SSID: the household's and the unit's
A household turns over every year or two. A smart lock does not. Keeping the two lifecycles separate is what stops a move-out becoming an outage.
Issue with the tenancy
Create the household's key when the tenancy is signed: from the console, in bulk from the move-in list when a block opens, or through the Purple API from your own lease system. Building devices are keyed once, at commissioning.
Place each household on its own VLAN
RADIUS returns the VLAN, role or group policy, depending on your vendor, with a bandwidth limit per key. Your access points enforce it, and any shared rule, such as a concierge printer, lives on your gateway.
Operate every block from one log
Every accept and reject carries its reason, by household, member of staff and device, across every block and streamed to Microsoft Sentinel, Splunk, Elastic or Datadog.
Revoke the household, keep the unit
At move-out the household's key is withdrawn and its live session ended with RADIUS CoA on access points that support it. The unit's locks and sensors keep the keys that were never the resident's.
One authentication log
One authentication log across every block you operate
Resident keys, staff certificates and building-device keys land in the same log, so a resident's "my WiFi is down" is a lookup on the key and not a site visit.
- Which households have joined since move-in, and which keys have never authenticated.
- Which locks, thermostats and leak sensors are authenticating at each block, and on which VLAN.
- Why a device was rejected: a revoked key, an expired key or an unbound MAC address.
- Whether a move-out's session ended when the key was withdrawn.
- Which contractor keys are still live after the job's end date.
Works with
Your directory, your MDM, your SIEM, your access points
Nothing is replaced. Purple Access sits on the systems your team already runs.
Identity providers
Over SAML and SCIM. Group membership decides the VLAN.- Microsoft Entra ID
- Okta
- Google Workspace
Device management
EAP-TLS certificates delivered over SCEP, with a compliance-gated join.- Microsoft Intune
- Jamf Pro
- JumpCloud
- Kandji
- Hexnode
- Iru
- Addigy
SIEM
The authentication log, over webhook or syslog.- Microsoft Sentinel
- Splunk
- Elastic
- Datadog
Access points
Mixed estates are supported.- Cisco Meraki
- HPE Aruba
- Ruckus
- Juniper Mist
- Ubiquiti UniFi
- Cambium
- Extreme
- Fortinet
Identity providers: setup and mappingDevice management: setup and mappingSIEM: setup and mappingHardware setup by vendor
Proof
Resident networks at scale
About 1 million students and residents run on Purple's community networks, and US university housing across 40 buildings saw 60% fewer helpdesk tickets at move-in.
- ~1M
- students and residents on Purple community networks
- 60%
- fewer helpdesk tickets at move-in, US university housing across 40 buildings
- 99.9%
- cloud RADIUS uptime SLA, in your contract
- 99.999%
- uptime, with a 99.9% cloud RADIUS SLA and multi-region failover
Add-on: Purple Shield
Add protective DNS with Purple Shield
Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.
FAQ
Questions IT leads ask
Do we need new access points in our blocks?
No. Purple Access is a cloud overlay on the access points your blocks already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.
Is xPSK one SSID or one per household, tenant or device?
One SSID. Every key on it has its own VLAN, policy and bandwidth limit, returned by RADIUS at authentication, and there is no per-SSID key ceiling. Adding a key never adds a beacon.
Is xPSK the same as iPSK, PPSK, DPSK, MPSK or EasyPSK?
Yes. xPSK is our name for the capability each vendor ships under its own: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK. Purple runs all of them from one platform, on a mixed estate.
How can WiFi be live on move-in day with no broadband order?
Your building already has the bulk internet and the access points. The household's key is the only thing that is issued, from the console, in bulk from a list or through the Purple API, so there is nothing for the resident to order and nobody to send.
What exactly happens at move-out?
The household's key is revoked, its devices fail their next authentication and RADIUS CoA ends the live session on access points that support it. The unit's locks, thermostats and sensors authenticate on their own keys, so they stay up, and the next household gets a key of its own.
What does MAC binding do for phones with a private WiFi address?
It is strongest on fixed-MAC devices such as locks, thermostats, sensors and TVs. A phone with a private address presents one address per network, so the household key does its work on the VLAN and the log shows exactly what joined. Do not rely on MAC binding to survive a phone resetting its private address.
Book a demo: we issue and revoke a key on a live network
Bring one block's worth of devices: a resident's phone, a smart lock, a leak sensor and a concierge laptop. We issue each a key or a certificate, place it on its VLAN and revoke one live, on the access points you already run.
- Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
- We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
- You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.
Your design session
Your live key demo
A Purple network engineer runs the demo with you, on your kind of estate.