Higher education: eduroam for people, a personal WiFi key for devices it cannot connect, a portal for visitors
Staff authenticate with EAP-TLS from your MDM and students roam on Passpoint, with eduroam beside both. Consoles, smart TVs and speakers in halls, lab instruments and building systems each get a MAC-bound key and a VLAN, and visitors use the portal.
- Five-year Murray State deal
- University of New Brunswick on iPSK
- 53,000+ students
- 99.9% RADIUS uptime SLA
Who is on the higher education network
Who connects across a campus, and where each one lands
eduroam keeps the people whose devices can run 802.1X. Everything that cannot, games hardware, smart TVs, speakers, lab instruments and building systems, gets a MAC-bound key on a VLAN of its own, issued under an identity so it leaves when the account does.
| Who or what connects | Network | Authentication | Placement | What starts and ends access |
|---|---|---|---|---|
| Open day, conference and event visitors | Open | Captive portal sign-in, consent recorded (SSO, social or SMS) | Guest VLAN, client isolation on | Consent recorded at sign-in, then the session times out |
| Students on personal laptops and phones, with no MDM | Open | Purple app onboarding, certificate installed, no MDM (university account) | Onboarding lane, then the student VLAN | Ends with the directory account |
| Academic, professional services and research staff | Secure | EAP-TLS, certificate from your MDM over SCEP | VLAN or role by directory group | Account disabled once, and RADIUS CoA ends the session |
| Students moving between campus and city | Secure | Passpoint or OpenRoaming profile | Student VLAN, no portal on return | Profile installed once, valid across OpenRoaming |
| Consoles, smart TVs and speakers in halls | xPSK | Individual key, MAC-bound (issued under the student's account) | A student-device VLAN, a bandwidth limit per key | Ends with the account, or when revoked |
| Lab instruments and research devices | xPSK | Individual key, MAC-bound | A locked-down VLAN per lab or instrument class | Revoked when the instrument is decommissioned |
| Conference delegates and summer school visitors | xPSK | Individual key, MAC-bound (dated, issued in bulk) | A delegate VLAN with its own limit | Ends on the last day of the stay |
| Lifts, access control, building management and CCTV | xPSK | Individual key, MAC-bound | A building-systems VLAN, unreachable from people | Rotated or revoked per device by estates |
Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.
Higher education: open, secure and xPSK
Three networks, each doing its own job
Identity decides the VLAN inside each network, so one SSID carries many groups.
Visitors and unmanaged student devices
Visitors use the captive portal. Students with no MDM install a WiFi pass from the Purple app once.
- Open days and conferences on the portal. SSO, social or SMS sign-in, consent recorded for GDPR and CCPA, under 15 minutes to add to a controller.
- Student laptops and phones with no MDM. One sign-in in the Purple app with the university account installs a pass on Windows, macOS, Linux, iOS and Android.
- Visiting academics keep eduroam. A visitor authenticates to eduroam with home credentials. The portal covers everyone without a federated identity.
Staff and roaming students: EAP-TLS and Passpoint
One WPA-Enterprise SSID. Cloud RADIUS checks the directory and returns the VLAN for the group.
- EAP-TLS from your MDM. Microsoft Intune, Jamf Pro, JumpCloud, Kandji, Hexnode, Iru and Addigy deliver the certificate over SCEP. Setup is five to ten minutes, once.
- Directory groups decide the VLAN. Entra ID, Okta or Google Workspace over SAML and SCIM. Department and role map to a VLAN, and one disabled account stops everywhere.
- Passpoint for students on the move. One profile carries a student across campus, city and tram. OpenRoaming reaches 5 million+ hotspots, free through the Connect licence.
Halls, labs and plant: a key each, on its own VLAN
eduroam needs an 802.1X supplicant, and a console or a sequencer has none. To the device, an xPSK key is an ordinary WPA2-Personal passphrase.
- Consoles, TVs and speakers under the student's identity. The student signs in once and the app issues a MAC-bound key per device, so the key ends when the account does.
- Lab instruments and research devices. A key each and a locked-down VLAN per lab. The rule that lets a lab reach its data store lives on your gateway.
- Summer schools and conferences. Keys created in bulk from the delegate list with an end date, so access closes on the last day.
- Building systems apart from people. Lifts, access control, BMS and CCTV on device keys in their own VLAN, out of reach of student devices.
Lifecycle
Key lifecycle: enrol, place, operate, withdraw
The same four moves serve a student's console and a lab instrument, tied to your directory, asset register and delegate list.
Issue from the account or the asset register
Student keys come from the Purple app. Instruments and plant are keyed when registered, from the console, a bulk list or the Purple API, each bound to its MAC.
Place on a VLAN by group and device class
RADIUS returns the VLAN, role or group policy, depending on your vendor. Your access points enforce it and inter-VLAN rules stay on your gateway.
Operate from one log across every building
Every accept and reject carries its reason, by student, member of staff and device, streamed to Sentinel, Splunk, Elastic or Datadog.
End one device, one account or one stay
Retire an instrument and you revoke one key. Disable a leaver and their keys stop authenticating, with RADIUS CoA ending the live session.
One authentication log
One authentication log for the whole estate
Staff certificates, Passpoint profiles, hall devices and lab instruments land in one log, so "whose is this device" is a query, not a walk round the building.
- Which consoles, TVs and speakers in a hall belong to which student, and on which VLAN.
- Whether any lab instrument is on the student VLAN.
- Which accounts were rejected today, by which method, and why.
- Whether a leaver's devices dropped when the account was disabled.
Audit
Campus retail and catering: what a QSA tests against
Bookshops, cafes and payment kiosks on campus are merchants too. Purple never touches card data, and segmentation hands your assessor a VLAN map and a log.
PCI DSS v4.0.1 Req 2.3.2
Wireless keys must change when anyone who knows them leaves. A key per till means rotating one, not every register.PCI DSS Req 8 and 10
Every authentication is logged with the identity and the reason, streamed to your SIEM as evidence.
Works with
Your directory, your MDM, your SIEM, your access points
Nothing is replaced. Purple Access sits on the systems your team already runs.
Identity providers
Over SAML and SCIM. Group membership decides the VLAN.- Microsoft Entra ID
- Okta
- Google Workspace
Device management
EAP-TLS certificates delivered over SCEP, with a compliance-gated join.- Microsoft Intune
- Jamf Pro
- JumpCloud
- Kandji
- Hexnode
- Iru
- Addigy
SIEM
The authentication log, over webhook or syslog.- Microsoft Sentinel
- Splunk
- Elastic
- Datadog
Access points
Mixed estates are supported.- Cisco Meraki
- HPE Aruba
- Ruckus
- Juniper Mist
- Ubiquiti UniFi
- Cambium
- Extreme
- Fortinet
Identity providers: setup and mappingDevice management: setup and mappingSIEM: setup and mappingHardware setup by vendor
Proof
Universities run on it
Murray State signed for five years, the University of New Brunswick runs iPSK on Purple, and Newcastle's students roam between campus, city and trams.
- 5 years
- Murray State University's deal for Purple PSK WiFi
- iPSK
- University of New Brunswick runs iPSK on Purple
- 53,000+
- students roaming between campus, city and trams in Newcastle
- 60%
- fewer helpdesk tickets at move-in, US university housing across 40 buildings
Add-on: Purple Shield
Add protective DNS with Purple Shield
Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.
FAQ
Questions IT leads ask
Where does eduroam fit?
Beside the three, as its own SSID. In education, eduroam makes it four. Open, secure and xPSK carry your visitors, staff, halls and devices, and eduroam keeps doing its roaming job.
How does a console get on when it cannot do 802.1X?
The student signs in once in the Purple app with a Microsoft, Google or Okta account, and the app issues a passcode for the console. To the console it is an ordinary WPA2-Personal passphrase, with no supplicant and no portal. MAC binding ties the key to that console.
Do we need new access points?
No. Purple Access is a cloud overlay on the access points your campuses already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.
What happens to a student's devices when they leave or are suspended?
Their directory account is disabled once. Cloud RADIUS rejects the next authentication, the keys issued under that account stop, and RADIUS CoA ends the live session on access points that support it.
How does an instrument reach a data store without sitting on the student VLAN?
Its key places it on a lab VLAN. A rule letting that VLAN reach the data store is allowed by policy at your gateway or firewall. Purple decides the lane and logs why, and your gateway enforces who it can reach.
Is xPSK the same as iPSK, PPSK, DPSK, MPSK or EasyPSK?
Yes. xPSK is our name for the capability each vendor ships under its own: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK. Purple runs all of them from one platform, on a mixed estate.
Book a demo: we issue and revoke a key on a live network
Bring one hall's worth of devices: a console, a smart TV, a lab instrument and a staff laptop. We issue each a key or a certificate, place it on its VLAN and revoke one live, on the access points you already run.
- Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
- We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
- You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.
Your design session
Your live key demo
A Purple network engineer runs the demo with you, on your kind of estate.