Multifamily: a personal WiFi key per household, staff on EAP-TLS, visitors on the portal
Bulk internet delivered as managed, home-like WiFi in every unit: one xPSK SSID per community, one key and VLAN per household, and the same model on whichever access points each acquisition came with. Staff sign in on EAP-TLS and visitors use the portal, all in one log.
- 80,000+ venues in 90 countries
- 1,000+ connectors
- 99.9% RADIUS uptime SLA
Who is on the multifamily and apartments network
Who connects in a multifamily (MDU) apartment community, and where each one lands
Bulk internet delivered per unit across a mixed access point estate: the unit is a VLAN or role and not an SSID or a router, with one RADIUS and one dashboard across the portfolio, on any AP brand.
| Who or what connects | Network | Authentication | Placement | What starts and ends access |
|---|---|---|---|---|
| Prospects and visitors in the leasing office and clubhouse | Open | Captive portal sign-in, consent recorded (or SSO, social, SMS) | Guest VLAN, client isolation on | Consent recorded at sign-in, session expires on timeout |
| Maintenance staff on personal phones | Open | Purple app onboarding, certificate installed, no MDM | Onboarding lane, then the group VLAN | Ends with the directory account |
| Leasing and maintenance staff on managed devices | Secure | EAP-TLS, certificate from your MDM over SCEP | VLAN by directory group, per community | Account disabled, and RADIUS CoA ends the session |
| Regional and portfolio managers | Secure | Passpoint or OpenRoaming profile (or EAP-TLS) | A management VLAN at every community they cover | Profile installed once, valid wherever the platform runs |
| Leaseholders and their households | xPSK | Individual key, MAC-bound (one key per household) | A VLAN or role per unit, with its own bandwidth limit | Issued at lease signing, revoked at move-out |
| Property-owned devices: access control, cameras, leasing-office printers | xPSK | Individual key, MAC-bound (bound to the device's MAC) | A building-systems VLAN, unreachable from units | One key per device, revoked when the device is swapped |
| Vendors: cleaners, pest control, HVAC and repair crews | xPSK | Individual key, MAC-bound (time-limited, no MDM) | A vendor VLAN and bandwidth limit per key | Ends on the day the work order does |
Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.
Multifamily and apartments: open, secure and xPSK
Three networks, each doing its own job
Identity decides the VLAN inside each network, so one SSID carries many groups.
Prospects, visitors and staff phones: portal and onboarding lane
The public lane for the leasing office and clubhouse, and the onboarding lane for staff whose phones the property does not manage.
- A portal per community. Sign-in methods and branding per property, with consent recorded for GDPR and CCPA. Under 15 minutes to add the splash URL and RADIUS to a controller.
- Maintenance phones with no MDM. Sign in once in the Purple app and a WiFi pass installs, on Windows, macOS, Linux, iOS and Android, then the phone lands on its group VLAN.
Property staff and portfolio managers: EAP-TLS and Passpoint
One WPA-Enterprise SSID per community. Cloud RADIUS checks the directory and returns the VLAN for the group, so leasing, maintenance and the regional team each land in their own lane.
- EAP-TLS from your MDM. Microsoft Intune, Jamf Pro, JumpCloud, Kandji, Hexnode, Iru and Addigy deliver the certificate over SCEP. Setup is five to ten minutes, once, for the whole organisation.
- Groups span communities. Entra ID, Okta or Google Workspace over SAML and SCIM. A group lands on its VLAN at every community, and a leaver is disabled once for the whole portfolio.
- Passpoint for people who visit several communities. Install a profile once and join every community that runs the platform, with OpenRoaming free through the Connect licence.
Units and property devices: a key each, on its own VLAN
A resident's laptop and a camera over the leasing office door share nothing, not even an 802.1X supplicant, so each gets its own key on one SSID. There is no per-SSID key ceiling.
- Bulk internet delivered per unit. Your uplink is one pool, and each key returns its own VLAN, policy and bandwidth limit, so a unit behaves like home broadband on shared infrastructure.
- One portfolio, one dashboard, any AP brand. Communities acquired on different access points run through the same RADIUS and the same dashboard, under each vendor's own name for the capability.
- Vendors with nothing to install. A time-limited key from the self-service portal or the Purple API, ending on the day the work order does.
Lifecycle
Lease-up, occupancy, turnover: one key lifecycle per household
Multifamily turns over in waves, with a lease-up at opening and a rolling cycle after. The same four moves handle both, tied to your lease list and your directory.
Issue in bulk at lease-up
Create a community's household keys from the lease list when it opens, then one at a time as leases sign, from the console or through the Purple API. Property devices are keyed once, at commissioning.
Place each unit on its own VLAN
RADIUS returns the VLAN, role or group policy, depending on each community's vendor, with a bandwidth limit per key. The access points enforce it, and rules between VLANs live on your gateway.
Operate the portfolio from one log
Every accept and reject carries its reason, by community, unit and device, whichever access point brand answered, streamed to Microsoft Sentinel, Splunk, Elastic or Datadog.
Revoke at turnover, not at the building
A move-out withdraws one key and ends its live session with RADIUS CoA on access points that support it. Neighbouring units and the property's own devices keep their keys.
One authentication log
One authentication log across communities and AP brands
Acquisitions rarely share a controller vendor, so per-controller logs mean five consoles and no portfolio view. One RADIUS gives one record, whichever access point answered.
- Which units authenticated in the last day at each community, and on which VLAN.
- Which property devices are authenticating, and which have dropped off since last week.
- Why a resident's device was rejected: a revoked key, an expired key or an unbound MAC address.
- Which vendor keys are still live after their work order closed.
- How authentication volume compares across communities on different AP brands.
Works with
Your directory, your MDM, your SIEM, your access points
Nothing is replaced. Purple Access sits on the systems your team already runs.
Identity providers
Over SAML and SCIM. Group membership decides the VLAN.- Microsoft Entra ID
- Okta
- Google Workspace
Device management
EAP-TLS certificates delivered over SCEP, with a compliance-gated join.- Microsoft Intune
- Jamf Pro
- JumpCloud
- Kandji
- Hexnode
- Iru
- Addigy
SIEM
The authentication log, over webhook or syslog.- Microsoft Sentinel
- Splunk
- Elastic
- Datadog
Access points
Mixed estates are supported.- Cisco Meraki
- HPE Aruba
- Ruckus
- Juniper Mist
- Ubiquiti UniFi
- Cambium
- Extreme
- Fortinet
Identity providers: setup and mappingDevice management: setup and mappingSIEM: setup and mappingHardware setup by vendor
Proof
A platform built for estates, not single sites
About 1 million students and residents run on Purple's community networks, and every community on the platform reports into the same log.
- 80,000+
- venues run on Purple, in 90 countries
- ~1M
- students and residents on Purple community networks
- 1,000+
- connectors to the tools you already run
- 99.9%
- cloud RADIUS uptime SLA, in your contract
Add-on: Purple Shield
Add protective DNS with Purple Shield
Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.
FAQ
Questions IT leads ask
Do we need to standardise on one access point brand?
No. Purple Access is a cloud overlay on the access points your communities already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.
Is xPSK one SSID or one per household, tenant or device?
One SSID. Every key on it has its own VLAN, policy and bandwidth limit, returned by RADIUS at authentication, and there is no per-SSID key ceiling. Adding a key never adds a beacon.
Is xPSK the same as iPSK, PPSK, DPSK, MPSK or EasyPSK?
Yes. xPSK is our name for the capability each vendor ships under its own: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK. Purple runs all of them from one platform, on a mixed estate.
We acquired communities on Meraki, Aruba and Ruckus. Is that one platform?
Yes. Each vendor's per-device key feature has its own name and its own RADIUS attributes, and Purple runs all of them from one platform. The unit's VLAN or role is returned in the form each vendor expects, so the portfolio keeps one RADIUS, one dashboard and one log.
What stops one unit reaching another's devices?
Each household's key returns its own VLAN or role with client isolation on, so the access points never bridge one unit to another. Any exception, such as a shared printer in the leasing office, is a rule you write at the gateway.
What stops a resident passing their key to the next unit?
MAC binding ties the key to the household's devices, so a copied key fails on a device it was not bound to. It is strongest on fixed-MAC devices such as TVs and sensors, and the log shows every rejection with its reason.
Book a demo: we issue and revoke a key on a live network
Bring two communities on different access point brands. We issue a household key at each, place it on its unit VLAN, revoke one live and show you the single log both land in.
- Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
- We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
- You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.
Your design session
Your live key demo
A Purple network engineer runs the demo with you, on your kind of estate.