Schools: visitors on the portal, directory groups for people, a personal WiFi key per display and supply teacher
Staff and pupils authenticate against Google Workspace or Entra ID, with a VLAN per group. A supply teacher gets a key for exactly the days booked, classroom displays and printers get MAC-bound device keys, and visitors use the portal.
- 80,000+ venues in 90 countries
- ISO 27001 and Cyber Essentials Plus
- 99.9% RADIUS uptime SLA
- 500 million logins a year
Who is on the schools network
Who connects in a school, and where each one lands
A school's cast changes weekly: temporary staff arrive for a day and leavers must vanish without a ticket. Access follows the directory and a calendar date, not a shared password, and classroom displays and printers sit on keys of their own.
| Who or what connects | Network | Authentication | Placement | What starts and ends access |
|---|---|---|---|---|
| Governors or board members, parents and event visitors | Open | Captive portal sign-in, consent recorded | Guest VLAN, client isolation on | Consent recorded at sign-in, then the session times out |
| Staff and older pupils on personal devices | Open | Purple app onboarding, certificate installed, no MDM (school account) | Onboarding lane, then the group VLAN | Ends with the directory account |
| Teachers and school staff on managed laptops | Secure | EAP-TLS, certificate from your MDM over SCEP (from Intune or Jamf Pro) | VLAN or role by directory group | Account disabled once, and RADIUS CoA ends the session |
| Pupils on school-managed laptops and tablets | Secure | EAP-TLS, certificate from your MDM over SCEP | A pupil VLAN with its own policy | Ends with the pupil's directory account |
| Short-term staff: supply teachers and visiting specialists | xPSK | Individual key, MAC-bound (dated to the booking, no MDM) | A staff-access VLAN with its own limit | Ends on the last booked day |
| Classroom displays, printers and tablet carts | xPSK | Individual key, MAC-bound | A device VLAN per class of device | One key per device, revoked when swapped |
| Cleaners, caterers and maintenance contractors | xPSK | Individual key, MAC-bound (time-limited, nothing to install) | A contractor VLAN, a limit per key | Ends on the contract's end date |
| Heating controls, CCTV, door entry and bells | xPSK | Individual key, MAC-bound | A building-systems VLAN, unreachable from pupils | Rotated or revoked per device by the site team |
Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.
Schools: open, secure and xPSK
Three networks, each doing its own job
Identity decides the VLAN inside each network, so one SSID carries many groups.
Visitors and personal devices
Parents and event visitors use the captive portal. Staff and older pupils with their own devices join once through the Purple app.
- Open evenings and parent events on the portal. SSO, social or SMS sign-in, consent recorded for GDPR and CCPA, under 15 minutes to add to a controller.
- Personal devices with no MDM. One sign-in in the Purple app with the school's Google, Microsoft or Okta account installs a pass on Windows, macOS, Linux, iOS and Android.
- Guests apart from pupils. The guest VLAN has client isolation on and no route to the pupil or staff VLANs.
Staff and pupils: directory groups decide the VLAN
One WPA-Enterprise SSID for managed devices. Cloud RADIUS checks the directory and returns the VLAN or role for the group.
- EAP-TLS from your MDM. Microsoft Intune, Jamf Pro, JumpCloud, Kandji, Hexnode, Iru and Addigy deliver the certificate over SCEP. Setup is five to ten minutes, once.
- Leavers off from the directory. Google Workspace or Entra ID over SAML and SCIM. A leaver is disabled once, and their certificate stops being accepted.
- A policy per VLAN, set once. Each group lands on its own VLAN, so Purple Shield can set a different DNS filtering policy for staff, pupils and guests.
Short-term staff and classroom devices: a key each
Anyone or anything with no directory account, no MDM or no 802.1X supplicant gets a key. To the device it is an ordinary WPA2-Personal passphrase.
- A key for exactly the days booked. Issued from the console or the Purple API with a start and an end date. No directory account, nothing installed, and it stops when the booking ends.
- Displays, printers and tablet carts. Each on a MAC-bound key and a device VLAN, so a swapped display is one revocation and a key is never a second shared password.
- Contractors and caterers. A time-limited key from the self-service portal or the Purple API, ending on the day the contract does.
Lifecycle
Key lifecycle: book, place, operate, close
The same four moves serve a supply teacher and a wall display, tied to the staff booking, the directory and the site's asset list.
Issue from the booking or the asset list
A supply teacher's key is created with the booking's dates. Displays and printers are keyed when fitted, from the console, a bulk list or the Purple API, each bound to its MAC.
Place on a VLAN by group and device class
RADIUS returns the VLAN, role or group policy, depending on your vendor. Your access points and gateway enforce it, and inter-VLAN rules live on your gateway.
Operate from one log across every site
Every accept and reject carries its reason, by member of staff, pupil and device, streamed to Sentinel, Splunk, Elastic or Datadog.
Close on the date, or when the directory says
A booking key stops on its last day. A leaver is disabled once in the directory, and RADIUS CoA ends the live session on access points that support it.
One authentication log
One authentication log across every site
Staff certificates, booking keys and device keys land in one log, so "who is on the network today, and should they be" is a query.
- Which supply teacher keys are live today, and which expired on schedule.
- Which classroom devices are on the network at each site, and on which VLAN.
- Which accounts were rejected, by which method, and why.
- Which contractor keys are still live after the contract ended.
Audit
Filtering duties: what the VLAN map and the log evidence
Duties differ by country. A VLAN per group puts each policy where it applies, and the log shows which device was on which VLAN. Evidence, not a claim of compliance.
DfE filtering and monitoring standards
Schools need to show filtering and monitoring is in place. A VLAN per group carries each policy, and the log shows which device sat where, and when.
Works with
Your directory, your MDM, your SIEM, your access points
Nothing is replaced. Purple Access sits on the systems your team already runs.
Identity providers
Over SAML and SCIM. Group membership decides the VLAN.- Google Workspace
- Microsoft Entra ID
- Okta
Device management
EAP-TLS certificates delivered over SCEP, with a compliance-gated join.- Microsoft Intune
- Jamf Pro
- JumpCloud
- Kandji
- Hexnode
- Iru
- Addigy
SIEM
The authentication log, over webhook or syslog.- Microsoft Sentinel
- Splunk
- Elastic
- Datadog
Access points
Mixed estates are supported.- Cisco Meraki
- HPE Aruba
- Ruckus
- Juniper Mist
- Ubiquiti UniFi
- Cambium
- Extreme
- Fortinet
Identity providers: setup and mappingDevice management: setup and mappingSIEM: setup and mappingHardware setup by vendor
Proof
A platform you can put in front of a governor
ISO 27001 and Cyber Essentials Plus are held by Purple, and the RADIUS SLA is in your contract.
- 80,000+
- venues run on Purple, in 90 countries
- 500M
- logins a year
- ISO 27001
- and Cyber Essentials Plus, held by Purple
- 99.9%
- cloud RADIUS uptime SLA, in your contract
Add-on: Purple Shield
Add protective DNS with Purple Shield
Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.
FAQ
Questions IT leads ask
How does a supply teacher get on without a directory account?
A key with a start and an end date, issued from the console or the Purple API. It needs no account, no MDM and nothing installed, and it stops on the last booked day.
How does a classroom display with no browser and no supplicant get on?
To the display, its xPSK key is an ordinary WPA2-Personal passphrase. MAC binding ties the key to that display, so it cannot become a second shared password, and swapping the display is one revocation.
Do we need new access points?
No. Purple Access is a cloud overlay on the access points your schools and sites already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.
Can a group of schools run every site from one place?
Yes. One cloud RADIUS and one authentication log cover every site, with your directory deciding the VLAN, on a mixed estate of access point brands.
How does content filtering apply to pupils, staff and guests?
Each group lands on its own VLAN, and Purple Shield sets a DNS policy per VLAN and by time of day. Shield bolts onto Access or runs standalone, and the filtering follows the VLAN, not the access point.
Is xPSK the same as iPSK, PPSK, DPSK, MPSK or EasyPSK?
Yes. xPSK is our name for the capability each vendor ships under its own: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK. Purple runs all of them from one platform, on a mixed estate.
Book a demo: we issue and revoke a key on a live network
Bring one school's worth of devices: a supply teacher's phone, a wall display, a printer and a staff laptop. We issue each a key or a certificate, place it on its VLAN and revoke one live, on the access points you already run.
- Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
- We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
- You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.
Your design session
Your live key demo
A Purple network engineer runs the demo with you, on your kind of estate.