Skip to content
Residential: Military and service family housing

Military housing: a personal WiFi key per home, housing staff on EAP-TLS, visitors on the portal

Each service family gets one xPSK key and its own VLAN or role, issued in bulk ahead of the posting. Housing staff sign in on EAP-TLS, visitors use the portal, and estate systems keep their own keys, on the access points you already own.

  • 80,000+ venues in 90 countries
  • ISO 27001 and Cyber Essentials Plus
  • 99.9% RADIUS uptime SLA
Illustration
Illustration: one xPSK SSID with a unique key per device, resident, tenant and contractor, each on its own VLAN and bandwidth limit, revocable on its own.
Book my design session

Who is on the military and service family housing network

Who connects on a service family accommodation estate, and where each one lands

A posting is a lifecycle event at estate scale: households arrive and leave in batches, so each home is a VLAN and a key issued and revoked in bulk from the allocation list.

Who connects on a service family accommodation estate, and where each one lands
Who or what connectsNetworkAuthenticationPlacementWhat starts and ends access
Housing staff on personal phonesOpenPurple app onboarding, certificate installed, no MDMOnboarding lane, then the group VLANEnds with the directory account
Visiting family and groups in community hallsOpenCaptive portal sign-in, consent recorded (or SSO, social, SMS)Guest VLAN, client isolation onConsent recorded at sign-in, session expires on timeout
Housing office and welfare staff on managed devicesSecureEAP-TLS, certificate from your MDM over SCEPVLAN by directory groupAccount disabled, and RADIUS CoA ends the session
Service families, home by homexPSKIndividual key, MAC-bound (one key per home)A VLAN or role per home, with client isolation onIssued ahead of arrival, revoked at departure
Estate entry barriers, CCTV and street-lighting controllersxPSKIndividual key, MAC-bound (bound to the device's MAC)An estate-systems VLAN, unreachable from homesOne key per device, revoked when the device is swapped
Maintenance contractorsxPSKIndividual key, MAC-bound (time-limited, no MDM)A contractor VLAN and bandwidth limit per keyEnds on the day the job does

Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.

Military and service family housing: open, secure and xPSK

Three networks, each doing its own job

Identity decides the VLAN inside each network, so one SSID carries many groups.

Visitors, community halls and staff phones: portal and onboarding lane

Everyone who is not a resident of a home or a member of the housing team gets the guest lane, and never a family's VLAN.

  • Community halls and welfare centres on the portal. Sign-in by SSO, Google, Apple, Facebook or SMS, with consent recorded for GDPR and CCPA and client isolation on. Under 15 minutes to add the splash URL and RADIUS to a controller.
  • Staff phones with no MDM. Sign in once in the Purple app and a WiFi pass installs, on Windows, macOS, Linux, iOS and Android, then the phone lands on its group VLAN.
Illustration

Lifecycle

Posting in, posting out: one key per home per occupancy

The system of record is your housing allocation list. Arrivals and departures cluster around posting dates, so the lifecycle is built to run in bulk.

Issue ahead of the posting

Create the incoming families' keys from the allocation list before the move, in bulk from the console or through the Purple API. Estate systems are keyed once, at commissioning.

Illustration

Place each home on its own VLAN

RADIUS returns the VLAN, role or group policy, depending on each estate's vendor. The access points enforce it, and rules between VLANs live on your gateway.

Illustration

Operate every estate from one log

Every accept and reject carries its reason, by estate, home and device, and streams to Microsoft Sentinel, Splunk, Elastic or Datadog.

Illustration

Withdraw the departing key, in bulk if needed

A departure withdraws that home's key and ends its live session with RADIUS CoA on access points that support it. A batch of departures is the same action across a list, and no other home is touched.

Illustration

One authentication log

One authentication log across every estate and posting cycle

Posting season is a spike in issuance and revocation. One log shows what was issued, what joined and what was withdrawn, estate by estate.

  • Which homes' keys have never authenticated since arrival, estate by estate.
  • Which keys were withdrawn at departure, and whether their live sessions ended.
  • Why a device was rejected: a revoked key, an expired key or an unbound MAC address.
  • Which estate systems are authenticating, and on which VLAN.
  • Which contractor keys are still live after the job closed.
Illustration

Works with

Your directory, your MDM, your SIEM, your access points

Nothing is replaced. Purple Access sits on the systems your team already runs.

  • Identity providers

    Over SAML and SCIM. Group membership decides the VLAN.
    • Microsoft Entra ID
    • Okta
    • Google Workspace
  • Device management

    EAP-TLS certificates delivered over SCEP, with a compliance-gated join.
    • Microsoft Intune
    • Jamf Pro
    • JumpCloud
    • Kandji
    • Hexnode
    • Iru
    • Addigy
  • SIEM

    The authentication log, over webhook or syslog.
    • Microsoft Sentinel
    • Splunk
    • Elastic
    • Datadog
  • Access points

    Mixed estates are supported.
    • Cisco Meraki
    • HPE Aruba
    • Ruckus
    • Juniper Mist
    • Ubiquiti UniFi
    • Cambium
    • Extreme
    • Fortinet

Proof

Platform assurance, in writing

Purple holds ISO 27001 and Cyber Essentials Plus, and the cloud RADIUS SLA is a floor we commit to in your contract.

80,000+
venues run on Purple, in 90 countries
500M
logins a year
99.9%
cloud RADIUS uptime SLA, in your contract
99.999%
uptime, with a 99.9% cloud RADIUS SLA and multi-region failover

Add-on: Purple Shield

Add protective DNS with Purple Shield

Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.

Illustration

FAQ

Questions IT leads ask

Do we need new access points on our estates?

No. Purple Access is a cloud overlay on the access points your estates already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.

Is xPSK one SSID or one per household, tenant or device?

One SSID. Every key on it has its own VLAN, policy and bandwidth limit, returned by RADIUS at authentication, and there is no per-SSID key ceiling. Adding a key never adds a beacon.

Is xPSK the same as iPSK, PPSK, DPSK, MPSK or EasyPSK?

Yes. xPSK is our name for the capability each vendor ships under its own: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK. Purple runs all of them from one platform, on a mixed estate.

How can a home be online the day a family arrives?

The estate already has the uplink and the access points, so the only thing to issue is the family's key. Create it from the allocation list before the posting, and the first device to join authenticates on it with no account to set up and no engineer to send.

How do we handle a hundred departures and arrivals in one week?

Keys are created and withdrawn in bulk from a list, from the console or through the Purple API. Each withdrawal is one key, so a batch does not touch any home that is staying.

What does sealed off from every other home mean technically?

Each home's key returns its own VLAN or role with client isolation on, so devices on one home's VLAN cannot reach another's. That is policy enforced by the access points and your gateway, a logical boundary and not a physical one.

What assurance does Purple hold?

Purple holds ISO 27001 and Cyber Essentials Plus. The platform logs every authentication with its reason for your own assurance work, and it does not itself confer any accreditation on your estate.

Book a demo: we issue and revoke a key on a live network

Bring one estate's worth of devices: a family's phone, an entry barrier, a housing officer's laptop and a contractor's phone. We issue each a key or a certificate, place it on its VLAN and revoke one live, on the access points you already run.

  1. Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
  2. We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
  3. You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.

Your design session

Your live key demo

A Purple network engineer runs the demo with you, on your kind of estate.