Corporate offices: EAP-TLS for laptops, the portal for visitors, a personal WiFi key beyond 802.1X
Managed laptops and phones stay on EAP-TLS. Printers, displays, meeting-room kit and sensors have no supplicant, so each gets its own MAC-bound key, and visitors sign in on the portal. Your directory drives joiners and leavers on all three networks, with one authentication log.
- JPMorgan runs staff WiFi on Purple across 5,000 branches
- 80% fewer IT helpdesk requests at McDonald's
- ISO 27001 and Cyber Essentials Plus
- 99.9% RADIUS uptime SLA
Phones, laptops, tills, CCTV and TVs join through your access point. Cloud RADIUS checks each one and sends it to the open, secure or xPSK network by identity, each on its own VLAN; a leaver whose account is disabled is rejected.
Who is on the corporate offices network
Who connects, and where each one lands
Certificates for every device that can hold one, a personal key for everything 802.1X cannot reach, and one directory driving joiners and leavers across all three networks.
| Who or what connects | Network | Authentication | Placement | What starts and ends access |
|---|---|---|---|---|
| Employees on unmanaged personal devices | Open | Purple app onboarding, certificate installed, no MDM | Onboarding lane, then the group VLAN | Ends with the directory account |
| Visitors and interview candidates | Open | Captive portal sign-in, consent recorded | Guest VLAN, client isolation on | Consent recorded at sign-in |
| Employees on managed laptops and phones | Secure | EAP-TLS, certificate from your MDM over SCEP | VLAN or role by directory group | Account disabled when HR removes it, and RADIUS CoA ends the session |
| Contractors and agency staff | xPSK | Individual key, MAC-bound (time-limited, nothing to install) | A VLAN and bandwidth limit per key | Ends on its end date |
| Printers and multifunction devices | xPSK | Individual key, MAC-bound | A print VLAN, reachable from user VLANs by policy at your gateway | Revoked when the device is swapped |
| Displays, meeting-room panels and video kit | xPSK | Individual key, MAC-bound | A room-systems VLAN | One key per device, rotated or revoked alone |
| Sensors, badge readers and building controls | xPSK | Individual key, MAC-bound | A building-systems VLAN, apart from users | Revoked when the unit is replaced |
Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.
Corporate offices: open, secure and xPSK
Three networks, each doing its own job
Identity decides the VLAN inside each network, so one SSID carries many groups.
Visitors and unmanaged devices: portal and onboarding lane
The guest lane for people who are not staff, and the BYOD lane for staff devices your MDM does not manage.
- A visitor portal, kept off the corporate LAN. Visitors sign in with SSO, Google, Apple or SMS on a guest-only VLAN with client isolation on. Consent is recorded for GDPR and CCPA.
- Personal phones with no MDM enrolment. Sign in once in the Purple app with a Microsoft, Google or Okta account and a certificate-backed WiFi pass installs, on Windows, macOS, Linux, iOS and Android.
- A lane from portal to certificate. A device starts on the open network and graduates to a certificate or a Passpoint profile, so the onboarding lane ends on the secure network.
Employees: EAP-TLS and directory groups
One WPA-Enterprise SSID. Cloud RADIUS checks the directory, evaluates posture and returns the VLAN or role for the group.
- EAP-TLS from your MDM. Microsoft Intune, Jamf Pro, JumpCloud, Kandji, Hexnode, Iru and Addigy deliver the certificate over SCEP. Setup is five to ten minutes, once, and Purple runs the certificate authority.
- Joiners have WiFi before day one. Users and groups sync over SCIM, so a joiner's first authentication, on day one or earlier, returns the VLAN for their groups.
- Leavers lose it when HR removes them. Disable the account in Entra ID, Okta or Google Workspace and the next authentication is rejected, with RADIUS CoA ending the live session.
Printers, displays, sensors and contractors: a key each
xPSK runs beside the 802.1X SSID. A device that can hold a certificate stays on it, and nothing changes for a managed laptop.
- Printers, each on its own key. A MAC-bound key and VLAN per printer, so a printer's key rotates alone. Who may reach it is policy at your gateway.
- Displays, room kit and sensors. No supplicant, no screen, no certificate store: each gets a key and a device VLAN, issued in bulk from your asset register or through the Purple API.
- Contractors with nothing to install. A time-limited key from the self-service portal or the Purple API, ending on the day the engagement does.
- One xPSK SSID beside the certificate SSID. The key lives on the access point side, under each vendor's name, so a printer sees an ordinary WPA2-Personal passphrase.
Lifecycle
Key lifecycle: from asset register to decommission
The systems of record are the ones you already run: your HR system and directory for people, your asset register for devices.
Issue at installation
Key a printer or display when it is installed: from the console, in bulk from your asset list or through the Purple API. Each key is bound to the device's MAC address.
Place on a VLAN by class and group
RADIUS returns the VLAN, role or group policy, depending on your vendor, for a device class or a directory group. Your access points and gateway enforce it.
Operate from one log
Certificates and keys land in the same log with the reason for each accept and reject, streamed to Microsoft Sentinel, Splunk, Elastic or Datadog.
End a device or a leaver
Retire a printer and you revoke its key alone. Remove a leaver in HR and the certificate stops being accepted, with RADIUS CoA ending the live session.
One authentication log
One log for certificates and keys
People and things authenticate differently and show up in the same place, so the exceptions to 802.1X are as visible as the rule.
- Which devices are on a key rather than a certificate, and which VLAN each landed on.
- Which accounts were rejected after HR removed them, and when the session ended.
- Which keys were presented from a MAC address they are not bound to, and rejected.
- Which contractor keys are live today, and when each ends.
Audit
Access control and logging: what your auditor samples
Your auditor asks who can reach what and how access ends. The group-to-VLAN map and the authentication log answer both.
ISO 27001 access control and logging
A group-to-VLAN map and an authentication log with the reason for every accept and reject, as evidence. Purple holds ISO 27001 and Cyber Essentials Plus.Cyber Essentials user access control
A leaver's WiFi ends when the directory account does, and the log shows the rejection.
Works with
Your directory, your MDM, your SIEM, your access points
Nothing is replaced. Purple Access sits on the systems your team already runs.
Identity providers
Over SAML and SCIM. Group membership decides the VLAN.- Microsoft Entra ID
- Okta
- Google Workspace
Device management
EAP-TLS certificates delivered over SCEP, with a compliance-gated join.- Microsoft Intune
- Jamf Pro
- JumpCloud
- Kandji
- Hexnode
- Iru
- Addigy
SIEM
The authentication log, over webhook or syslog.- Microsoft Sentinel
- Splunk
- Elastic
- Datadog
Access points
Mixed estates are supported.- Cisco Meraki
- HPE Aruba
- Ruckus
- Juniper Mist
- Ubiquiti UniFi
- Cambium
- Extreme
- Fortinet
Identity providers: setup and mappingDevice management: setup and mappingSIEM: setup and mappingHardware setup by vendor
Proof
Staff WiFi at estate scale
JPMorgan runs staff WiFi on Purple across 5,000 branches, and McDonald's cut IT helpdesk requests by 80%.
- 5,000
- JPMorgan branches on Purple staff WiFi
- 80%
- fewer IT helpdesk requests at McDonald's
- ISO 27001
- and Cyber Essentials Plus, held by Purple
- 99.9%
- cloud RADIUS uptime SLA, in your contract
Add-on: Purple Shield
Add protective DNS with Purple Shield
Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.
FAQ
Questions IT leads ask
Why not certificates for everything?
Certificates stay the default for every device that can hold one: staff laptops and phones on EAP-TLS, delivered by your MDM over SCEP. xPSK is for everything that cannot, such as devices with no 802.1X supplicant, no screen or no certificate store.
Is xPSK the same as iPSK, PPSK, DPSK, MPSK or EasyPSK?
Yes. xPSK is our name for the capability each vendor ships under its own: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK. Purple runs all of them from one platform, on a mixed estate.
Do we need new access points?
No. Purple Access is a cloud overlay on the access points your offices already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.
Does this replace our NAC?
For WiFi access control, yes: compliance-gated join, Conditional Access, device posture and MDM enrolment state at authentication, from Microsoft Intune, Jamf Pro, JumpCloud, Kandji, Hexnode, Iru and Addigy. Migration is usually a weekend exercise.
What about devices with no MDM, like student laptops and personal phones?
They sign in once in the Purple app with their work or university account, Microsoft, Google or Okta, and a WiFi pass installs on the device. Windows, macOS, Linux, iOS and Android, with no MDM.
What does revoking one key do to everyone else?
Nothing. Each key is its own entry in RADIUS, bound to its device by MAC, so withdrawing one ends that device's access and leaves every other key connected. A live session is ended with RADIUS CoA on access points that support it.
Book a demo: we issue and revoke a key on a live network
Bring the list of what 802.1X cannot reach: the printers, displays, room kit and sensors on your floor. We issue each a key, place it on its VLAN and revoke one live, beside the certificates you already run.
- Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
- We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
- You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.
Your design session
Your live key demo
A Purple network engineer runs the demo with you, on your kind of estate.