Smart buildings: visitors on the portal, staff on EAP-TLS, a personal WiFi key per device
Lifts, EV chargers, building controls, cameras and signage each join with a MAC-bound key on their own VLAN, with no certificate and no portal. Facilities staff sit on EAP-TLS, visitors use the portal, and all three land in one authentication log.
- 99.9% RADIUS uptime SLA
- 1,000+ connectors
- 80,000+ venues in 90 countries
Who is on the smart buildings and iot network
What connects to a building, and the network each one lands on
One leaked shared password exposes every device on it, so each lift controller, EV charger and camera gets its own MAC-bound key and VLAN: one leak opens one device, and a device with no screen and no certificate store never needs either.
| Who or what connects | Network | Authentication | Placement | What starts and ends access |
|---|---|---|---|---|
| Facilities staff on personal phones | Open | Purple app onboarding, certificate installed, no MDM | Onboarding lane, then the group VLAN | Ends with the directory account |
| Visitors, occupants' guests and deliveries | Open | Captive portal sign-in, consent recorded | Guest VLAN, client isolation on | Consent recorded at sign-in, session ends on timeout |
| Building owner and facilities team laptops and phones | Secure | EAP-TLS, certificate from your MDM over SCEP | VLAN by directory group, apart from every device class | Account disabled in the directory ends access |
| Lift, HVAC, EV charging and security contractors | xPSK | Individual key, MAC-bound (time-limited, no MDM) | A contractor VLAN and bandwidth limit per key | Ends on the job's end date |
| Lift controllers, HVAC and building management controllers | xPSK | Individual key, MAC-bound | A building-systems VLAN per class, apart from people | One key per controller, revoked when it is swapped |
| EV chargers | xPSK | Individual key, MAC-bound | A charger VLAN with its own bandwidth limit | Issued at commissioning, revoked at decommissioning |
| CCTV cameras and digital signage | xPSK | Individual key, MAC-bound | A camera VLAN and a signage VLAN, crossings set at your gateway | One key per device, rotated or revoked alone |
| Occupancy, air quality and leak sensors | xPSK | Individual key, MAC-bound | A sensor VLAN, apart from controls and people | One key per sensor, so rotating one touches none of the rest |
Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.
Smart buildings and IoT: open, secure and xPSK
Three networks, each doing its own job
Identity decides the VLAN inside each network, so one SSID carries many groups.
Visitors and staff phones: portal and onboarding lane
The guest lane and the BYOD onboarding lane. Neither can reach a building system, because each lands on a different VLAN from the device classes.
- Visitors on a portal, on a guest VLAN. Consent is recorded at sign-in and the session lands on a guest VLAN with client isolation on, so a visitor's laptop never shares a broadcast domain with a camera or a charger.
- Facilities staff phones with no MDM. Sign in once in the Purple app and a WiFi pass installs, then the phone moves to its directory group's VLAN.
- A new building in minutes. Add the splash URL and RADIUS to the controller in under 15 minutes, on the access points already in the ceiling.
Facilities and engineering staff: EAP-TLS and directory groups
One WPA-Enterprise SSID. Cloud RADIUS checks the directory and returns the VLAN for the group, so staff reach the BMS console and nothing reaches them.
- EAP-TLS from your MDM. Microsoft Intune, Jamf Pro, JumpCloud, Kandji, Hexnode, Iru and Addigy deliver the certificate over SCEP. Setup is five to ten minutes, once.
- Directory groups decide the VLAN. Facilities, security operations and finance land on separate VLANs from Entra ID, Okta or Google Workspace groups. What may cross to the building-systems VLAN is policy at your gateway.
- No RADIUS server in the plant room. Cloud RADIUS replaces an on-site server to patch and back up, with a 99.9% RADIUS uptime SLA in your contract and multi-region failover behind it.
Everything with no screen and no certificate store: a key each, a VLAN each
Building systems join on one xPSK SSID. MAC binding stops a key becoming a second shared password, and a VLAN per device class keeps a leak to one device.
- Lifts, EV chargers and building controls. Each on a MAC-bound key and a VLAN per class, so a charger swap revokes one key and a leaked key opens one device.
- Cameras and signage. Their own VLANs, with a bandwidth limit per key that caps what each one can take from the uplink.
- Devices with no screen. No captive portal to complete, no supplicant to configure and no certificate to install. The device is given a key and joins.
- Contractor engineers with nothing to install. A time-limited key from the self-service portal or the Purple API, ending on the day the job does.
Lifecycle
Key lifecycle: commission, place, operate, decommission
The same four moves cover a lift controller, a charger and a contractor, tied to the records a building already keeps: the commissioning sheet, the asset register and the directory.
Issue from the commissioning sheet
Import the device list from the commissioning sheet, or issue from the console or the Purple API as an installer commissions each unit. Every key is bound to the device's MAC address.
Place on a VLAN by device class
RADIUS returns the VLAN, role or group policy, depending on your vendor. Your access points enforce it, and the rule for what the BMS console may reach lives on your gateway.
Operate from one log across every building
Every accept and reject carries the device, the key, the VLAN and the reason, for staff, contractors and devices alike, streamed to Microsoft Sentinel, Splunk, Elastic or Datadog.
Revoke one device, or one contractor
Replace a charger and you revoke its key alone. A contractor's key ends on its date, and RADIUS CoA ends a live session on access points that support it.
One authentication log
One authentication log for the building's people and its devices
Lifts, chargers, staff certificates and contractor keys land in the same log, so "what is this device and who looks after it" is a query and not a walk of the plant room.
- Which devices are on the network now, by class, and on which VLAN.
- Which devices tried to join with a revoked or unknown key, and when.
- Which contractor keys authenticated this week, and which ended on their date.
- Whether a decommissioned device's key still authenticates anywhere.
- Which staff authenticated by EAP-TLS, which were rejected, and why.
Works with
Your directory, your MDM, your SIEM, your access points
Nothing is replaced. Purple Access sits on the systems your team already runs.
Identity providers
Over SAML and SCIM. Group membership decides the VLAN.- Microsoft Entra ID
- Okta
- Google Workspace
Device management
EAP-TLS certificates delivered over SCEP, with a compliance-gated join.- Microsoft Intune
- Jamf Pro
- JumpCloud
- Kandji
- Hexnode
- Iru
- Addigy
SIEM
The authentication log, over webhook or syslog.- Microsoft Sentinel
- Splunk
- Elastic
- Datadog
Access points
Mixed estates are supported.- Cisco Meraki
- HPE Aruba
- Ruckus
- Juniper Mist
- Ubiquiti UniFi
- Cambium
- Extreme
- Fortinet
Identity providers: setup and mappingDevice management: setup and mappingSIEM: setup and mappingHardware setup by vendor
Proof
The platform behind the building
80,000+ venues in 90 countries run on Purple, with a 99.9% RADIUS uptime SLA in your contract.
- 80,000+
- venues run on Purple, in 90 countries
- 99.9%
- cloud RADIUS uptime SLA, in your contract
- 1,000+
- connectors to the tools you already run
Add-on: Purple Shield
Add protective DNS with Purple Shield
Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.
FAQ
Questions IT leads ask
Do we need new access points for building systems?
No. Purple Access is a cloud overlay on the access points your buildings already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.
How does a controller with no screen and no supplicant get on?
To the controller, its xPSK key is an ordinary WPA2-Personal passphrase, so there is no supplicant and no portal. The per-device key lives on the access point side, under each vendor's name for it: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK.
What does a leaked key expose?
One device, on its own VLAN. Revoke the key and a RADIUS CoA ends its live session on access points that support it, while every other device keeps its own key. A shared password is different: one leak exposes every device on it.
Does MAC binding hold on every device?
It is strongest on fixed-MAC devices, which is most of a building: controllers, chargers, cameras, signage players and sensors. A phone that randomises its address belongs on EAP-TLS or the Purple app, not on a device key.
Can the BMS console still reach the controllers?
Yes, by policy at your gateway or firewall. Purple returns the VLAN or role at authentication, and your gateway decides what may cross between VLANs, such as the console reaching controllers and nothing reaching it back.
Does a VLAN per device class mean an SSID per class?
No. One xPSK SSID carries every key and RADIUS returns the VLAN, so adding a class adds keys and never beacons. 8 to 10 SSIDs use 15 to 25% of channel airtime, which is why three networks is the design.
Book a demo: we issue and revoke a key on a live network
Bring the list of what is on your building network: a lift controller, a charger, a camera and a contractor's laptop. We issue each a key or a certificate, place it on its VLAN and revoke one live.
- Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
- We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
- You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.
Your design session
Your live key demo
A Purple network engineer runs the demo with you, on your kind of estate.