Skip to content
Work and commercial: Corporate offices

Corporate offices: EAP-TLS for laptops, the portal for visitors, a personal WiFi key beyond 802.1X

Managed laptops and phones stay on EAP-TLS. Printers, displays, meeting-room kit and sensors have no supplicant, so each gets its own MAC-bound key, and visitors sign in on the portal. Your directory drives joiners and leavers on all three networks, with one authentication log.

  • JPMorgan runs staff WiFi on Purple across 5,000 branches
  • 80% fewer IT helpdesk requests at McDonald's
  • ISO 27001 and Cyber Essentials Plus
  • 99.9% RADIUS uptime SLA

Phones, laptops, tills, CCTV and TVs join through your access point. Cloud RADIUS checks each one and sends it to the open, secure or xPSK network by identity, each on its own VLAN; a leaver whose account is disabled is rejected.

Every deviceYour access pointsCloud RADIUSRejected: account disabled
Open
  • Captive portal sign-in
  • Consent recorded
  • BYOD onboarding lane
Secure
  • EAP-TLS from your MDM
  • Identity decides the VLAN
  • Passpoint and OpenRoaming
xPSK
  • A key per device
  • Own VLAN and bandwidth limit
  • Revoke one key alone
VLAN 10VLAN 20VLAN 40
Book my design session

Who is on the corporate offices network

Who connects, and where each one lands

Certificates for every device that can hold one, a personal key for everything 802.1X cannot reach, and one directory driving joiners and leavers across all three networks.

Who connects, and where each one lands
Who or what connectsNetworkAuthenticationPlacementWhat starts and ends access
Employees on unmanaged personal devicesOpenPurple app onboarding, certificate installed, no MDMOnboarding lane, then the group VLANEnds with the directory account
Visitors and interview candidatesOpenCaptive portal sign-in, consent recordedGuest VLAN, client isolation onConsent recorded at sign-in
Employees on managed laptops and phonesSecureEAP-TLS, certificate from your MDM over SCEPVLAN or role by directory groupAccount disabled when HR removes it, and RADIUS CoA ends the session
Contractors and agency staffxPSKIndividual key, MAC-bound (time-limited, nothing to install)A VLAN and bandwidth limit per keyEnds on its end date
Printers and multifunction devicesxPSKIndividual key, MAC-boundA print VLAN, reachable from user VLANs by policy at your gatewayRevoked when the device is swapped
Displays, meeting-room panels and video kitxPSKIndividual key, MAC-boundA room-systems VLANOne key per device, rotated or revoked alone
Sensors, badge readers and building controlsxPSKIndividual key, MAC-boundA building-systems VLAN, apart from usersRevoked when the unit is replaced

Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.

Corporate offices: open, secure and xPSK

Three networks, each doing its own job

Identity decides the VLAN inside each network, so one SSID carries many groups.

Visitors and unmanaged devices: portal and onboarding lane

The guest lane for people who are not staff, and the BYOD lane for staff devices your MDM does not manage.

  • A visitor portal, kept off the corporate LAN. Visitors sign in with SSO, Google, Apple or SMS on a guest-only VLAN with client isolation on. Consent is recorded for GDPR and CCPA.
  • Personal phones with no MDM enrollment. Sign in once in the Purple app with a Microsoft, Google or Okta account and a certificate-backed WiFi pass installs, on Windows, macOS, Linux, iOS and Android.
  • A lane from portal to certificate. A device starts on the open network and graduates to a certificate or a Passpoint profile, so the onboarding lane ends on the secure network.
Illustration

Lifecycle

Key lifecycle: from asset register to decommission

The systems of record are the ones you already run: your HR system and directory for people, your asset register for devices.

Issue at installation

Key a printer or display when it is installed: from the console, in bulk from your asset list or through the Purple API. Each key is bound to the device's MAC address.

Illustration

Place on a VLAN by class and group

RADIUS returns the VLAN, role or group policy, depending on your vendor, for a device class or a directory group. Your access points and gateway enforce it.

Illustration

Operate from one log

Certificates and keys land in the same log with the reason for each accept and reject, streamed to Microsoft Sentinel, Splunk, Elastic or Datadog.

Illustration

End a device or a leaver

Retire a printer and you revoke its key alone. Remove a leaver in HR and the certificate stops being accepted, with RADIUS CoA ending the live session.

Illustration

One authentication log

One log for certificates and keys

People and things authenticate differently and show up in the same place, so the exceptions to 802.1X are as visible as the rule.

  • Which devices are on a key rather than a certificate, and which VLAN each landed on.
  • Which accounts were rejected after HR removed them, and when the session ended.
  • Which keys were presented from a MAC address they are not bound to, and rejected.
  • Which contractor keys are live today, and when each ends.
Illustration

Audit

Access control and logging: what your auditor samples

Your auditor asks who can reach what and how access ends. The group-to-VLAN map and the authentication log answer both.

  • ISO 27001 access control and logging

    A group-to-VLAN map and an authentication log with the reason for every accept and reject, as evidence. Purple holds ISO 27001 and Cyber Essentials Plus.

Works with

Your directory, your MDM, your SIEM, your access points

Nothing is replaced. Purple Access sits on the systems your team already runs.

  • Identity providers

    Over SAML and SCIM. Group membership decides the VLAN.
    • Microsoft Entra ID
    • Okta
    • Google Workspace
  • Device management

    EAP-TLS certificates delivered over SCEP, with a compliance-gated join.
    • Microsoft Intune
    • Jamf Pro
    • JumpCloud
    • Kandji
    • Hexnode
    • Iru
    • Addigy
  • SIEM

    The authentication log, over webhook or syslog.
    • Microsoft Sentinel
    • Splunk
    • Elastic
    • Datadog
  • Access points

    Mixed estates are supported.
    • Cisco Meraki
    • HPE Aruba
    • Ruckus
    • Juniper Mist
    • Ubiquiti UniFi
    • Cambium
    • Extreme
    • Fortinet

Proof

Staff WiFi at estate scale

JPMorgan runs staff WiFi on Purple across 5,000 branches, and McDonald's cut IT helpdesk requests by 80%.

5,000
JPMorgan branches on Purple staff WiFi
80%
fewer IT helpdesk requests at McDonald's
ISO 27001
and Cyber Essentials Plus, held by Purple
99.9%
cloud RADIUS uptime SLA, in your contract

Add-on: Purple Shield

Add protective DNS with Purple Shield

Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.

Illustration

FAQ

Questions IT leads ask

Why not certificates for everything?

Certificates stay the default for every device that can hold one: staff laptops and phones on EAP-TLS, delivered by your MDM over SCEP. xPSK is for everything that cannot, such as devices with no 802.1X supplicant, no screen or no certificate store.

Is xPSK the same as iPSK, PPSK, DPSK, MPSK or EasyPSK?

Yes. xPSK is our name for the capability each vendor ships under its own: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK. Purple runs all of them from one platform, on a mixed estate.

Do we need new access points?

No. Purple Access is a cloud overlay on the access points your offices already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.

How is a printer key different from a shared office password?

A shared password is one secret for everyone and rotates for nobody. A device key belongs to one printer, bound to its MAC address, so a copied key fails from another device and rotating it means one device.

Does this replace our NAC?

For WiFi access control, yes: compliance-gated join, Conditional Access, device posture and MDM enrollment state at authentication, from Microsoft Intune, Jamf Pro, JumpCloud, Kandji, Hexnode, Iru and Addigy. Migration is usually a weekend exercise.

What about devices with no MDM, like student laptops and personal phones?

They sign in once in the Purple app with their work or university account, Microsoft, Google or Okta, and a WiFi pass installs on the device. Windows, macOS, Linux, iOS and Android, with no MDM.

What does revoking one key do to everyone else?

Nothing. Each key is its own entry in RADIUS, bound to its device by MAC, so withdrawing one ends that device's access and leaves every other key connected. A live session is ended with RADIUS CoA on access points that support it.

Book a demo: we issue and revoke a key on a live network

Bring the list of what 802.1X cannot reach: the printers, displays, room kit and sensors on your floor. We issue each a key, place it on its VLAN and revoke one live, beside the certificates you already run.

  1. Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
  2. We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
  3. You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.

Your design session

Your live key demo

A Purple network engineer runs the demo with you, on your kind of estate.