Skip to content
Operations and IoT: Smart buildings and IoT

Smart buildings: visitors on the portal, staff on EAP-TLS, a personal WiFi key per device

Lifts, EV chargers, building controls, cameras and signage each join with a MAC-bound key on their own VLAN, with no certificate and no portal. Facilities staff sit on EAP-TLS, visitors use the portal, and all three land in one authentication log.

  • 99.9% RADIUS uptime SLA
  • 1,000+ connectors
  • 80,000+ venues in 90 countries
Illustration
Illustration: one xPSK SSID with a unique key per device, resident, tenant and contractor, each on its own VLAN and bandwidth limit, revocable on its own.
Book my design session

Who is on the smart buildings and iot network

What connects to a building, and the network each one lands on

One leaked shared password exposes every device on it, so each lift controller, EV charger and camera gets its own MAC-bound key and VLAN: one leak opens one device, and a device with no screen and no certificate store never needs either.

What connects to a building, and the network each one lands on
Who or what connectsNetworkAuthenticationPlacementWhat starts and ends access
Facilities staff on personal phonesOpenPurple app onboarding, certificate installed, no MDMOnboarding lane, then the group VLANEnds with the directory account
Visitors, occupants' guests and deliveriesOpenCaptive portal sign-in, consent recordedGuest VLAN, client isolation onConsent recorded at sign-in, session ends on timeout
Building owner and facilities team laptops and phonesSecureEAP-TLS, certificate from your MDM over SCEPVLAN by directory group, apart from every device classAccount disabled in the directory ends access
Lift, HVAC, EV charging and security contractorsxPSKIndividual key, MAC-bound (time-limited, no MDM)A contractor VLAN and bandwidth limit per keyEnds on the job's end date
Lift controllers, HVAC and building management controllersxPSKIndividual key, MAC-boundA building-systems VLAN per class, apart from peopleOne key per controller, revoked when it is swapped
EV chargersxPSKIndividual key, MAC-boundA charger VLAN with its own bandwidth limitIssued at commissioning, revoked at decommissioning
CCTV cameras and digital signagexPSKIndividual key, MAC-boundA camera VLAN and a signage VLAN, crossings set at your gatewayOne key per device, rotated or revoked alone
Occupancy, air quality and leak sensorsxPSKIndividual key, MAC-boundA sensor VLAN, apart from controls and peopleOne key per sensor, so rotating one touches none of the rest

Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.

Smart buildings and IoT: open, secure and xPSK

Three networks, each doing its own job

Identity decides the VLAN inside each network, so one SSID carries many groups.

Visitors and staff phones: portal and onboarding lane

The guest lane and the BYOD onboarding lane. Neither can reach a building system, because each lands on a different VLAN from the device classes.

  • Visitors on a portal, on a guest VLAN. Consent is recorded at sign-in and the session lands on a guest VLAN with client isolation on, so a visitor's laptop never shares a broadcast domain with a camera or a charger.
  • Facilities staff phones with no MDM. Sign in once in the Purple app and a WiFi pass installs, then the phone moves to its directory group's VLAN.
  • A new building in minutes. Add the splash URL and RADIUS to the controller in under 15 minutes, on the access points already in the ceiling.
Illustration

Lifecycle

Key lifecycle: commission, place, operate, decommission

The same four moves cover a lift controller, a charger and a contractor, tied to the records a building already keeps: the commissioning sheet, the asset register and the directory.

Issue from the commissioning sheet

Import the device list from the commissioning sheet, or issue from the console or the Purple API as an installer commissions each unit. Every key is bound to the device's MAC address.

Illustration

Place on a VLAN by device class

RADIUS returns the VLAN, role or group policy, depending on your vendor. Your access points enforce it, and the rule for what the BMS console may reach lives on your gateway.

Illustration

Operate from one log across every building

Every accept and reject carries the device, the key, the VLAN and the reason, for staff, contractors and devices alike, streamed to Microsoft Sentinel, Splunk, Elastic or Datadog.

Illustration

Revoke one device, or one contractor

Replace a charger and you revoke its key alone. A contractor's key ends on its date, and RADIUS CoA ends a live session on access points that support it.

Illustration

One authentication log

One authentication log for the building's people and its devices

Lifts, chargers, staff certificates and contractor keys land in the same log, so "what is this device and who looks after it" is a query and not a walk of the plant room.

  • Which devices are on the network now, by class, and on which VLAN.
  • Which devices tried to join with a revoked or unknown key, and when.
  • Which contractor keys authenticated this week, and which ended on their date.
  • Whether a decommissioned device's key still authenticates anywhere.
  • Which staff authenticated by EAP-TLS, which were rejected, and why.
Illustration

Works with

Your directory, your MDM, your SIEM, your access points

Nothing is replaced. Purple Access sits on the systems your team already runs.

  • Identity providers

    Over SAML and SCIM. Group membership decides the VLAN.
    • Microsoft Entra ID
    • Okta
    • Google Workspace
  • Device management

    EAP-TLS certificates delivered over SCEP, with a compliance-gated join.
    • Microsoft Intune
    • Jamf Pro
    • JumpCloud
    • Kandji
    • Hexnode
    • Iru
    • Addigy
  • SIEM

    The authentication log, over webhook or syslog.
    • Microsoft Sentinel
    • Splunk
    • Elastic
    • Datadog
  • Access points

    Mixed estates are supported.
    • Cisco Meraki
    • HPE Aruba
    • Ruckus
    • Juniper Mist
    • Ubiquiti UniFi
    • Cambium
    • Extreme
    • Fortinet

Proof

The platform behind the building

80,000+ venues in 90 countries run on Purple, with a 99.9% RADIUS uptime SLA in your contract.

80,000+
venues run on Purple, in 90 countries
99.9%
cloud RADIUS uptime SLA, in your contract
1,000+
connectors to the tools you already run

Add-on: Purple Shield

Add protective DNS with Purple Shield

Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.

Illustration

FAQ

Questions IT leads ask

Do we need new access points for building systems?

No. Purple Access is a cloud overlay on the access points your buildings already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.

How does a controller with no screen and no supplicant get on?

To the controller, its xPSK key is an ordinary WPA2-Personal passphrase, so there is no supplicant and no portal. The per-device key lives on the access point side, under each vendor's name for it: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK.

What does a leaked key expose?

One device, on its own VLAN. Revoke the key and a RADIUS CoA ends its live session on access points that support it, while every other device keeps its own key. A shared password is different: one leak exposes every device on it.

Does MAC binding hold on every device?

It is strongest on fixed-MAC devices, which is most of a building: controllers, chargers, cameras, signage players and sensors. A phone that randomises its address belongs on EAP-TLS or the Purple app, not on a device key.

Can the BMS console still reach the controllers?

Yes, by policy at your gateway or firewall. Purple returns the VLAN or role at authentication, and your gateway decides what may cross between VLANs, such as the console reaching controllers and nothing reaching it back.

Does a VLAN per device class mean an SSID per class?

No. One xPSK SSID carries every key and RADIUS returns the VLAN, so adding a class adds keys and never beacons. 8 to 10 SSIDs use 15 to 25% of channel airtime, which is why three networks is the design.

Book a demo: we issue and revoke a key on a live network

Bring the list of what is on your building network: a lift controller, a charger, a camera and a contractor's laptop. We issue each a key or a certificate, place it on its VLAN and revoke one live.

  1. Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
  2. We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
  3. You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.

Your design session

Your live key demo

A Purple network engineer runs the demo with you, on your kind of estate.