Many organisations, one building: every tenant sealed on its own VLAN, with a personal WiFi key per device
Each tenant wants its own network, and building one per tenant is slow and costly. One set of access points returns a VLAN or role per organisation, keys and certificates ride on it, and the landlord keeps one dashboard and one log.
- Vancouver International Airport
- Kinetic Melbourne Airport
- 80,000+ venues in 90 countries
The problem
A network per tenant does not scale: radios, uplinks and SSIDs all multiply
Tenants want their own network, assessors want proof of separation and the landlord wants one set of radios. Building a network per tenant answers the first and breaks the other two.
- An SSID per tenant: 8 to 10 SSIDs use 15 to 25% of channel airtime, before a single client sends data.
- One shared password across tenants, so a leaver at one company still knows the key to every other company's printers.
- Every joiner, leaver and new device is a ticket to the landlord's IT team.
- Evidence that one tenant cannot reach another's network is a slide in a deck, not a log.
How it works
Issue, bind and place, operate, revoke
One organisation is the unit. Everything beneath it, people and devices, inherits its VLAN or role.
One organisation, one key set
Create the organisation once. Its staff sign in on the tenant's own Entra ID, Okta or Google Workspace, and its devices get keys from the console, in bulk from a list, or through the Purple API.
Bind to a device, place on the tenant's VLAN
Each key is bound to the device's MAC address, and RADIUS returns the organisation's VLAN or role with its own bandwidth limit. Your access points enforce it, and a shared-service rule, such as a common printer, lives on your gateway.
One log across every organisation
Every accept and reject carries the organisation, the method and the reason, so the landlord answers which tenant, which device and why from one place, and streams it to the SIEM.
Revoke one device, one person or one tenant
Withdraw a key and only that device drops, with RADIUS CoA ending its live session on access points that support it. A tenant that leaves has its keys revoked and nobody else is touched.
Open, secure or xPSK
Which of the three networks, for which party in the building
| Who or what connects | Network | Authentication | Placement | What starts and ends access |
|---|---|---|---|---|
| Visitors at reception, shoppers and the public | Open | Captive portal sign-in, consent recorded | A guest VLAN with client isolation on | Session and consent recorded at sign-in |
| Landlord and building management staff | Secure | EAP-TLS, certificate from your MDM over SCEP | A landlord VLAN, by directory group | Account disabled in the directory ends access |
| A tenant's laptops and phones | Secure | EAP-TLS, certificate from your MDM over SCEP (the tenant's own MDM and directory) | The tenant's own VLAN or role | Ends when the tenant disables the account, or the tenancy ends |
| A tenant's printers, screens and tills | xPSK | Individual key, MAC-bound | The tenant's VLAN, apart from every other tenant | One key per device, revoked alone |
| Fit-out and maintenance contractors | xPSK | Individual key, MAC-bound (time-limited, no MDM) | One unit's VLAN only | Ends on the date set, with nothing to uninstall |
| Lifts, HVAC and access control | xPSK | Individual key, MAC-bound | A building-systems VLAN, apart from every tenant | One key per controller, revoked with the device |
Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.
What it covers
What you can do with it
A VLAN or role per organisation
RADIUS returns it at authentication, so the SSID never has to change when a tenant arrives.Keys in bulk, ended on a date
A list of units, stands or staff becomes keys in one import, each with an end date.One SSID for every tenant
Tenant 51 adds keys, not beacons, so airtime is the same at 5 tenants and at 500.
Where it matters
The industries that run into this most
Airports
Airlines, handlers, concessions and agencies on one terminal's access points, a role and VLAN per organisation.Shopping malls
A VLAN and key set per retailer, so each tenant's assessor tests that tenant's VLAN map and authentication log.Multi-tenant office buildings
The landlord owns the radios and the uplink, and each tenant owns its identity.Coworking and flex space
A member company is a VLAN or role, and its printers and screens live inside it.Film and TV studios
A private network per production on shared lot infrastructure, with keys timed to the contract.Ports
Operators, agents and hauliers on port-authority infrastructure, each on its own network.
Proof
Concessions on their own keys, at airport scale
Vancouver International Airport and Kinetic Melbourne Airport put their concessions on their own keys.
- Vancouver
- International Airport runs on Purple, concessions on their own keys
- Melbourne
- Kinetic Melbourne Airport runs on Purple, concessions on their own keys
- 80,000+
- venues run on Purple, in 90 countries
FAQ
Questions IT leads ask
How many tenants fit on one SSID?
One xPSK SSID carries every tenant, each on its own VLAN or role. There is no per-SSID key ceiling, so a new tenant adds keys and not beacons.
Do we need new access points?
No. Purple Access is a cloud overlay on the access points your buildings already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.
Who issues and revokes the keys?
The landlord's IT team, from the console or the Purple API, with a branded self-service portal for contractors. Each key is unique to one device and bound to it by MAC address.
Is a VLAN per tenant enough to keep tenants apart?
The VLAN separates tenants at layer 2, and your gateway or firewall decides what, if anything, may cross between them, such as a shared printer. Purple decides which VLAN each connection lands in and logs why.
What if parts of the building run different access point brands?
Purple runs each vendor's per-device key capability on a mixed estate: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK.
Does xPSK take our WiFi out of PCI scope?
Purple never touches payment card data. Each till and card machine sits on its own key and its own VLAN, apart from guests and staff, and every authentication is logged as evidence for PCI DSS Req 8 and 10. We hand your QSA the VLAN map and the authentication log to test against.
Book a demo: we issue and revoke a key on a live network
Bring the list of tenants and what each runs. We create two organisations, issue a key in each and revoke one live, on the access points you already own.
- Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
- We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
- You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.
Your design session
Your live key demo
A Purple network engineer runs the demo with you, on your kind of estate.