Skip to content
Travel and venues: Serviced apartments and long stay

Serviced apartments: guests on the portal, staff on EAP-TLS, a personal WiFi key per client and device

Guests who stay for weeks join on the portal, or on a key whose end date you set. Corporate clients' staff land on one company network across every apartment they hold. Smart locks and thermostats stay on their own keys through every changeover.

  • 80,000+ venues in 90 countries
  • 500 million logins a year
  • 99.9% RADIUS uptime SLA
  • 99.999% uptime
Illustration
Illustration: one xPSK SSID with a unique key per device, resident, tenant and contractor, each on its own VLAN and bandwidth limit, revocable on its own.
Book my design session

Who is on the serviced apartments and long stay network

Who is on the property network, and where each one lands

Unit devices keep their keys through every changeover, each guest's access ends on its own date, and a corporate client's staff share one company network across apartments.

Who is on the property network, and where each one lands
Who or what connectsNetworkAuthenticationPlacementWhat starts and ends access
Short-stay guestsOpenCaptive portal sign-in, consent recorded (or SSO, social, SMS)Guest VLAN, client isolation onConsent recorded at sign-in
Returning guestsSecurePasspoint or OpenRoaming profileGuest VLAN, with no portal on returnProfile installed once, valid at every property that runs it
Housekeeping, reception and operations staffSecureEAP-TLS, certificate from your MDM over SCEPVLAN by directory groupAccount disabled, and RADIUS CoA ends the session
Long-stay guestsxPSKIndividual key, MAC-bound (an end date set at issue)A guest-class VLAN, with a bandwidth limit per keyEnds on the date set, or revoked alone
A corporate client's staff, across several apartmentsxPSKIndividual key, MAC-bound (grouped under one company)One role and VLAN per corporate clientEnds with the client's contract, one client at a time
Smart locks, thermostats and leak sensorsxPSKIndividual key, MAC-boundA device VLAN per class, unreachable from guestsThe key outlives every guest and ends when the device is replaced
Maintenance and refurbishment contractorsxPSKIndividual key, MAC-bound (time-limited, no MDM)A VLAN and bandwidth limit per keyEnds on the day the job does

Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.

Serviced apartments and long stay: open, secure and xPSK

Three networks, each doing its own job

Identity decides the VLAN inside each network, so one SSID carries many groups.

Guests and cleaners' phones: portal and onboarding lane

The guest lane for the first night and the BYOD lane for staff who bring their own phone.

  • Sign-in methods per brand. SSO, Google, Apple, Facebook or SMS, and under 15 minutes to add the splash URL and RADIUS to a controller.
  • Cleaners and agency staff with no MDM. Sign in once in the Purple app and a WiFi pass installs on Windows, macOS, Linux, iOS and Android.
Illustration

Lifecycle

Key lifecycle: commission, place, operate, change over

Two lifetimes share one SSID: the unit's devices live as long as the hardware, a guest's key as long as the booking.

Issue to the unit and to the stay

Key each lock and thermostat at commissioning, and each long-stay guest or client's staff on arrival, from the console, in bulk or through the Purple API, with an end date from the booking.

Illustration

Place by class: guest, client, device

RADIUS returns a VLAN, role or group policy, depending on your vendor. Guests and unit devices land on separate VLANs, each corporate client gets one of its own, and inter-VLAN rules live on your gateway.

Illustration

Operate one log across the portfolio

Every accept and reject carries the building, the method and the reason, across every property, streamed to Microsoft Sentinel, Splunk, Elastic or Datadog.

Illustration

Change over one guest, one client or one device

A departure ends one key and the lock keeps its own. A client's contract ending revokes that client's keys alone, with RADIUS CoA ending live sessions on access points that support it.

Illustration

One authentication log

One authentication log across every building you operate

Guest, client, staff and device authentications share a log, so "is this lock online and on the right VLAN" is a query and not a site visit.

  • Which unit devices are online at each building, and on which VLAN.
  • Which long-stay keys are still live after their end date.
  • Which corporate client's staff authenticated today, and in which apartments.
Illustration

Works with

Your directory, your MDM, your SIEM, your access points

Nothing is replaced. Purple Access sits on the systems your team already runs.

  • Identity providers

    Over SAML and SCIM. Group membership decides the VLAN.
    • Microsoft Entra ID
    • Okta
    • Google Workspace
  • Device management

    EAP-TLS certificates delivered over SCEP, with a compliance-gated join.
    • Microsoft Intune
    • Jamf Pro
    • JumpCloud
    • Kandji
    • Hexnode
    • Iru
    • Addigy
  • SIEM

    The authentication log, over webhook or syslog.
    • Microsoft Sentinel
    • Splunk
    • Elastic
    • Datadog
  • Access points

    Mixed estates are supported.
    • Cisco Meraki
    • HPE Aruba
    • Ruckus
    • Juniper Mist
    • Ubiquiti UniFi
    • Cambium
    • Extreme
    • Fortinet

Proof

Run across a portfolio of buildings

80,000+
venues run on Purple, in 90 countries
500M
logins a year
~2M
people onboarded every day
99.9%
cloud RADIUS uptime SLA, in your contract

Add-on: Purple Shield

Add protective DNS with Purple Shield

Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.

Illustration

FAQ

Questions IT leads ask

Do we need new access points in each apartment building or aparthotel?

No. Purple Access is a cloud overlay on the access points your buildings already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.

Can a guest who stays for a month avoid the portal every week?

Yes. A Passpoint profile rejoins automatically on every return, and a key issued with an end date joins like an ordinary WPA2-Personal network until that date.

How does one corporate client's staff share a network across apartments?

The client is one role and VLAN, and every key issued to its staff returns it in any apartment. Revoking one person's key leaves the rest connected.

What happens to a lock or thermostat's key at changeover?

Nothing. The device keeps its key and VLAN, because its lifetime is the hardware's and not the guest's. Each key is bound to the device by MAC and held on the access point side under each vendor's name for it (Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK).

Is xPSK one SSID or one per household, tenant or device?

One SSID. Every key on it has its own VLAN, policy and bandwidth limit, returned by RADIUS at authentication, and there is no per-SSID key ceiling. Adding a key never adds a beacon.

Book a demo: we issue and revoke a key on a live network

Bring one apartment's worth of devices: a lock, a thermostat, a guest's laptop and a client's staff phone. We issue each a key, place it on its VLAN and revoke one live, on the access points you already run.

  1. Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
  2. We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
  3. You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.

Your design session

Your live key demo

A Purple network engineer runs the demo with you, on your kind of estate.