Skip to content
Education and public: Higher education

Higher education: eduroam for people, a personal WiFi key for devices it cannot connect, a portal for visitors

Staff authenticate with EAP-TLS from your MDM and students roam on Passpoint, with eduroam beside both. Consoles, smart TVs and speakers in halls, lab instruments and building systems each get a MAC-bound key and a VLAN, and visitors use the portal.

  • Five-year Murray State deal
  • University of New Brunswick on iPSK
  • 53,000+ students
  • 99.9% RADIUS uptime SLA
Illustration
Illustration: Entra ID, Okta and Google Workspace groups decide the VLAN for each certificate-based sign-in, and a leaver whose account is disabled is rejected with live sessions ended.
Book my design session

Who is on the higher education network

Who connects across a campus, and where each one lands

eduroam keeps the people whose devices can run 802.1X. Everything that cannot, games hardware, smart TVs, speakers, lab instruments and building systems, gets a MAC-bound key on a VLAN of its own, issued under an identity so it leaves when the account does.

Who connects across a campus, and where each one lands
Who or what connectsNetworkAuthenticationPlacementWhat starts and ends access
Open day, conference and event visitorsOpenCaptive portal sign-in, consent recorded (SSO, social or SMS)Guest VLAN, client isolation onConsent recorded at sign-in, then the session times out
Students on personal laptops and phones, with no MDMOpenPurple app onboarding, certificate installed, no MDM (university account)Onboarding lane, then the student VLANEnds with the directory account
Academic, professional services and research staffSecureEAP-TLS, certificate from your MDM over SCEPVLAN or role by directory groupAccount disabled once, and RADIUS CoA ends the session
Students moving between campus and citySecurePasspoint or OpenRoaming profileStudent VLAN, no portal on returnProfile installed once, valid across OpenRoaming
Consoles, smart TVs and speakers in hallsxPSKIndividual key, MAC-bound (issued under the student's account)A student-device VLAN, a bandwidth limit per keyEnds with the account, or when revoked
Lab instruments and research devicesxPSKIndividual key, MAC-boundA locked-down VLAN per lab or instrument classRevoked when the instrument is decommissioned
Conference delegates and summer school visitorsxPSKIndividual key, MAC-bound (dated, issued in bulk)A delegate VLAN with its own limitEnds on the last day of the stay
Lifts, access control, building management and CCTVxPSKIndividual key, MAC-boundA building-systems VLAN, unreachable from peopleRotated or revoked per device by estates

Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.

Higher education: open, secure and xPSK

Three networks, each doing its own job

Identity decides the VLAN inside each network, so one SSID carries many groups.

Visitors and unmanaged student devices

Visitors use the captive portal. Students with no MDM install a WiFi pass from the Purple app once.

  • Open days and conferences on the portal. SSO, social or SMS sign-in, consent recorded for GDPR and CCPA, under 15 minutes to add to a controller.
  • Student laptops and phones with no MDM. One sign-in in the Purple app with the university account installs a pass on Windows, macOS, Linux, iOS and Android.
  • Visiting academics keep eduroam. A visitor authenticates to eduroam with home credentials. The portal covers everyone without a federated identity.
Illustration

Lifecycle

Key lifecycle: enrol, place, operate, withdraw

The same four moves serve a student's console and a lab instrument, tied to your directory, asset register and delegate list.

Issue from the account or the asset register

Student keys come from the Purple app. Instruments and plant are keyed when registered, from the console, a bulk list or the Purple API, each bound to its MAC.

Illustration

Place on a VLAN by group and device class

RADIUS returns the VLAN, role or group policy, depending on your vendor. Your access points enforce it and inter-VLAN rules stay on your gateway.

Illustration

Operate from one log across every building

Every accept and reject carries its reason, by student, member of staff and device, streamed to Sentinel, Splunk, Elastic or Datadog.

Illustration

End one device, one account or one stay

Retire an instrument and you revoke one key. Disable a leaver and their keys stop authenticating, with RADIUS CoA ending the live session.

Illustration

One authentication log

One authentication log for the whole estate

Staff certificates, Passpoint profiles, hall devices and lab instruments land in one log, so "whose is this device" is a query, not a walk round the building.

  • Which consoles, TVs and speakers in a hall belong to which student, and on which VLAN.
  • Whether any lab instrument is on the student VLAN.
  • Which accounts were rejected today, by which method, and why.
  • Whether a leaver's devices dropped when the account was disabled.
Illustration

Audit

Campus retail and catering: what a QSA tests against

Bookshops, cafes and payment kiosks on campus are merchants too. Purple never touches card data, and segmentation hands your assessor a VLAN map and a log.

  • PCI DSS v4.0.1 Req 2.3.2

    Wireless keys must change when anyone who knows them leaves. A key per till means rotating one, not every register.
  • PCI DSS Req 8 and 10

    Every authentication is logged with the identity and the reason, streamed to your SIEM as evidence.

Works with

Your directory, your MDM, your SIEM, your access points

Nothing is replaced. Purple Access sits on the systems your team already runs.

  • Identity providers

    Over SAML and SCIM. Group membership decides the VLAN.
    • Microsoft Entra ID
    • Okta
    • Google Workspace
  • Device management

    EAP-TLS certificates delivered over SCEP, with a compliance-gated join.
    • Microsoft Intune
    • Jamf Pro
    • JumpCloud
    • Kandji
    • Hexnode
    • Iru
    • Addigy
  • SIEM

    The authentication log, over webhook or syslog.
    • Microsoft Sentinel
    • Splunk
    • Elastic
    • Datadog
  • Access points

    Mixed estates are supported.
    • Cisco Meraki
    • HPE Aruba
    • Ruckus
    • Juniper Mist
    • Ubiquiti UniFi
    • Cambium
    • Extreme
    • Fortinet

Proof

Universities run on it

Murray State signed for five years, the University of New Brunswick runs iPSK on Purple, and Newcastle's students roam between campus, city and trams.

5 years
Murray State University's deal for Purple PSK WiFi
iPSK
University of New Brunswick runs iPSK on Purple
53,000+
students roaming between campus, city and trams in Newcastle
60%
fewer helpdesk tickets at move-in, US university housing across 40 buildings

Add-on: Purple Shield

Add protective DNS with Purple Shield

Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.

Illustration

FAQ

Questions IT leads ask

Where does eduroam fit?

Beside the three, as its own SSID. In education, eduroam makes it four. Open, secure and xPSK carry your visitors, staff, halls and devices, and eduroam keeps doing its roaming job.

How does a console get on when it cannot do 802.1X?

The student signs in once in the Purple app with a Microsoft, Google or Okta account, and the app issues a passcode for the console. To the console it is an ordinary WPA2-Personal passphrase, with no supplicant and no portal. MAC binding ties the key to that console.

Do we need new access points?

No. Purple Access is a cloud overlay on the access points your campuses already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.

What happens to a student's devices when they leave or are suspended?

Their directory account is disabled once. Cloud RADIUS rejects the next authentication, the keys issued under that account stop, and RADIUS CoA ends the live session on access points that support it.

How does an instrument reach a data store without sitting on the student VLAN?

Its key places it on a lab VLAN. A rule letting that VLAN reach the data store is allowed by policy at your gateway or firewall. Purple decides the lane and logs why, and your gateway enforces who it can reach.

Is xPSK the same as iPSK, PPSK, DPSK, MPSK or EasyPSK?

Yes. xPSK is our name for the capability each vendor ships under its own: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK. Purple runs all of them from one platform, on a mixed estate.

Book a demo: we issue and revoke a key on a live network

Bring one hall's worth of devices: a console, a smart TV, a lab instrument and a staff laptop. We issue each a key or a certificate, place it on its VLAN and revoke one live, on the access points you already run.

  1. Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
  2. We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
  3. You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.

Your design session

Your live key demo

A Purple network engineer runs the demo with you, on your kind of estate.