Move-in and move-out: revoke one personal WiFi key, never the shared password
A shared passphrase has to change when anyone who knows it leaves, and changing it disconnects everybody else. With a personal WiFi key per household on one xPSK SSID (iPSK, PPSK, DPSK, MPSK), a move-out is one revocation and every other resident, lock and thermostat stays online.
- 60% fewer helpdesk tickets at move-in
- ~1 million residents on Purple
- University of New Brunswick on iPSK
The problem
A shared password turns every move-out into a network-wide event
One passphrase is held by every device on the SSID. It is a credential that cannot be taken back from one person without taking it from all of them.
- Changing the passphrase drops every device on the SSID at once, and each change is a mass reconnect of TVs, speakers, thermostats and locks.
- Not changing it leaves the previous occupant with a working key. The principle is written down in PCI DSS v4.0.1 Req 2.3.2 says wireless keys must change when anyone who knows them leaves.
- A device-by-device fix is a ticket per household, so a turnover peak such as September in student housing becomes a helpdesk queue.
- Locks, thermostats and leak sensors belong to the unit and not to the person, so they cannot follow the resident's phone to a new key.
How it works
Issue at move-in, revoke at move-out, touch nobody else
The household is the unit. Its keys are created from the lease or booking record and ended from the same place.
Create the household's keys from the record
A move-in creates the keys from the console, a bulk import or the Purple API, so they exist before arrival. Residents collect theirs in the Purple app with a Microsoft, Google or Okta account, or from a branded self-service portal.
Bind each key to a device and place it
MAC binding ties a key to its device, and RADIUS returns the household's VLAN or role with its own bandwidth limit. The unit's locks, thermostats and leak sensors carry device keys of their own, so they are not part of the tenancy.
Answer "why is this offline" from one log
Every accept and reject is logged with the key, the device, the VLAN and the reason, and streams to Microsoft Sentinel, Splunk, Elastic or Datadog. A move-in ticket is a search, not a site visit.
Revoke the household, end the live session
Withdraw the household's keys and RADIUS CoA ends their live sessions on access points that support it. Other households carry on, the unit's device keys stay online, and the next tenancy gets new keys on the same SSID.
Open, secure or xPSK
Which of the three networks, for which party at move-in and move-out
| Who or what connects | Network | Authentication | Placement | What starts and ends access |
|---|---|---|---|---|
| Prospects at viewings and visitors in reception | Open | Captive portal sign-in, consent recorded | A guest VLAN with client isolation on | Session and consent recorded at sign-in |
| On-site team, concierge and maintenance staff | Secure | EAP-TLS, certificate from your MDM over SCEP (managed devices, groups from Entra ID, Okta or Google Workspace) | VLAN by directory group | Account disabled in the directory ends access |
| Residents and their households | xPSK | Individual key, MAC-bound | A VLAN or role per household, with its own bandwidth limit | Issued at move-in and revoked at move-out, with nothing else changing |
| Locks, thermostats and leak sensors in the flat | xPSK | Individual key, MAC-bound | A device VLAN per class, apart from residents | Stay online between tenancies, revoked alone when replaced |
| Cleaners and turnover contractors | xPSK | Individual key, MAC-bound (time-limited, no MDM) | One unit's or one block's VLAN only | Ends on the date set, with nothing to uninstall |
Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.
What it covers
What you can do with it
Keys before arrival
Import the move-in list and the keys exist before the first box is unpacked. US university housing across 40 buildings saw 60% fewer helpdesk tickets at move-in.Room and unit swaps
A resident who changes flat or room keeps their keys, because placement follows the person. The unit's device keys stay with the unit.Keys timed to the stay
A summer let, a one-week stay or a twelve-month tenancy gets its end date at issue, so expiry is built in and not a chore.Devices that outlive tenancies
Thermostats, locks and leak sensors stay online between tenancy changes, so the next resident arrives to a building that already works.
Where it matters
The industries that run into this most
Build to rent
Resident keys follow the tenancy and device keys follow the unit, so one move-out never touches the locks.Multifamily and apartments
Bulk internet delivered per unit on a mixed access point estate: a household is a VLAN or role, not an SSID.Student accommodation
Keys before arrival, room swaps that carry devices, and eduroam left to do identity.Co-living
Key lifetime equals the booking, from one week to a year.Military and service family housing
Arrivals and departures handled as batch lifecycle events at each posting.Serviced apartments and long stay
Locks and thermostats survive every guest changeover while booking keys come and go.Coworking and flex space
Member staff follow their own company's directory, and event guests get a key for the event only.Care homes
Agency staff get a key that ends when the booking ends, and residents' devices stay private to them.
Proof
Turnover at university scale
US university housing across 40 buildings saw 60% fewer helpdesk tickets at move-in, and about 1 million students and residents run on Purple community networks.
- 60%
- fewer helpdesk tickets at move-in, US university housing across 40 buildings
- ~1M
- students and residents on Purple community networks
- iPSK
- University of New Brunswick runs iPSK on Purple
Add-on: Purple Shield
Add protective DNS with Purple Shield
Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.
FAQ
Questions IT leads ask
Why not rotate the shared password at each move-out?
One passphrase is held by every device on the SSID. Rotating it disconnects every household at once, and not rotating it leaves the leaver with a working key. A key per household turns a move-out into one revocation.
Is xPSK one SSID or one per household, tenant or device?
One SSID. Every key on it has its own VLAN, policy and bandwidth limit, returned by RADIUS at authentication, and there is no per-SSID key ceiling. Adding a key never adds a beacon.
What stops a key being passed to a neighbour?
MAC binding ties each key to its device, so a key cannot become a second shared password. It is strongest on fixed-address devices such as locks, TVs and sensors. A household that needs another device gets another key.
What does revoking one key do to everyone else?
Nothing. Each key is its own entry in RADIUS, bound to its device by MAC, so withdrawing one ends that device's access and leaves every other key connected. A live session is ended with RADIUS CoA on access points that support it.
Where do staff and visitors fit?
On the other two networks. Staff sign in on the secure network with EAP-TLS or directory groups, prospects and visitors on the open network through the portal, and each lands on its own VLAN. xPSK carries the households and the devices that cannot hold a certificate.
Do we need new access points?
No. Purple Access is a cloud overlay on the access points your buildings already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.
Is xPSK the same as iPSK, PPSK, DPSK, MPSK or EasyPSK?
Yes. xPSK is our name for the capability each vendor ships under its own: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK. Purple runs all of them from one platform, on a mixed estate.
Book a demo: we issue and revoke a key on a live network
Bring a move-out list and the devices that live in a unit. We issue a household's keys and revoke one live, while the rest of the network stays connected.
- Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
- We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
- You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.
Your design session
Your live key demo
A Purple network engineer runs the demo with you, on your kind of estate.