Skip to content
Operations and IoT: Film and TV studios

Film and TV studios: visitors on the portal, staff on EAP-TLS, a personal WiFi key per crew member

Each production gets a private network on shared studio infrastructure, with keys timed to the production's contract. Studio operations sit on EAP-TLS, visiting talent and visitors use the portal, and one lot runs every shoot without building a network per shoot.

  • 80,000+ venues in 90 countries
  • 99.9% RADIUS uptime SLA
  • 500 million logins a year
Illustration
Illustration: one xPSK SSID with a unique key per device, resident, tenant and contractor, each on its own VLAN and bandwidth limit, revocable on its own.
Book my design session

Who is on the film and tv studios network

Who and what connects on a lot, and where each one lands

Productions arrive, run for a contract's length and leave, and each needs its own VLAN on the lot's shared access points with keys that end when the contract does, so the studio never builds a network per shoot.

Who and what connects on a lot, and where each one lands
Who or what connectsNetworkAuthenticationPlacementWhat starts and ends access
Studio staff on personal phonesOpenPurple app onboarding, certificate installed, no MDMOnboarding lane, then the group VLANEnds with the directory account
Visiting talent, agents and driversOpenCaptive portal sign-in, consent recordedGuest VLAN, client isolation onConsent recorded at sign-in, session ends on timeout
Studio operations and facilities staffSecureEAP-TLS, certificate from your MDM over SCEPVLAN by directory group, apart from every productionAccount disabled in the directory ends access
Post-production houses on the lotSecureEAP-TLS, certificate from your MDM over SCEP (the house's own directory and MDM)The house's own VLAN or roleEnds when the house disables the account or the lease ends
Production crewxPSKIndividual key, MAC-bound (from the crew list, time-limited to the contract)The production's own VLANEnds on the wrap date set in the contract
On-set cameras, monitors and data cartsxPSKIndividual key, MAC-boundThe production's VLAN, apart from every other productionOne key per device, revoked alone
Stage doors, lighting controllers and access controlxPSKIndividual key, MAC-boundA studio-systems VLAN, apart from every productionOne key per controller, revoked with the device
Set construction and facilities contractorsxPSKIndividual key, MAC-bound (time-limited, no MDM)A contractor VLAN, crossings set at your gatewayEnds on the job's end date

Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.

Film and TV studios: open, secure and xPSK

Three networks, each doing its own job

Identity decides the VLAN inside each network, so one SSID carries many groups.

Visiting talent and studio staff phones: portal and onboarding lane

Everyone who is on the lot for a day or is not on a production, on VLANs that share nothing with a production's network.

  • Talent, agents and drivers on a portal. A captive portal records consent and lands the session on a guest VLAN with client isolation on, so a visitor's phone is never on a production's network.
  • Studio staff phones with no MDM. Sign in once in the Purple app and a WiFi pass installs, then the phone moves to its group's VLAN.
  • Every stage and office on one portal. Add the splash URL and RADIUS to the lot's controllers in under 15 minutes, on the access points already installed.
Illustration

Lifecycle

Production lifecycle: onboard, run, wrap, strike

The same four moves run for every production, tied to the paperwork a production already has: the contract, the crew list and the device list.

Issue from the contract and the crew list

Create the production, import the crew list and device list, or issue from the console or the Purple API. Each key is bound to its device's MAC address and carries the contract's wrap date.

Illustration

Place on the production's VLAN

RADIUS returns the production's VLAN, role or group policy, depending on your vendor, plus the bandwidth limit. Your access points enforce it, and anything a production may reach in the studio's systems is policy at your gateway.

Illustration

Operate from one log across every production

Every accept and reject carries the production, the key, the VLAN and the reason, so the lot answers which production, which device and why from one place.

Illustration

Revoke at wrap, one production at a time

A production that wraps has its keys revoked in one pass and no other production is touched. RADIUS CoA ends live sessions on access points that support it.

Illustration

One authentication log

One authentication log across every production on the lot

Crew keys, set kit, studio staff certificates and visitors land in the same log, tagged by production, so "who is on which shoot" is a query.

  • Which productions are live on the lot and how many keys each has authenticated today.
  • Which crew keys were rejected, with the VLAN they asked for and why.
  • Whether any key from a wrapped production still authenticates.
  • Which studio staff authenticated by EAP-TLS, and which post house they belong to.
Illustration

Audit

Separation an assessor can test

Purple supplies the evidence: a VLAN map and a log per production, with the assessment itself run by the studio's client and its security vendor.

  • A VLAN map per production

    Which keys belong to which production, and which VLAN each returns, exported for the assessor.
  • The authentication log

    Every accept and reject with the identity and the reason, streamed to your SIEM, so wrap and separation are shown and not asserted.

Works with

Your directory, your MDM, your SIEM, your access points

Nothing is replaced. Purple Access sits on the systems your team already runs.

  • Identity providers

    Over SAML and SCIM. Group membership decides the VLAN.
    • Microsoft Entra ID
    • Okta
    • Google Workspace
  • Device management

    EAP-TLS certificates delivered over SCEP, with a compliance-gated join.
    • Microsoft Intune
    • Jamf Pro
    • JumpCloud
    • Kandji
    • Hexnode
    • Iru
    • Addigy
  • SIEM

    The authentication log, over webhook or syslog.
    • Microsoft Sentinel
    • Splunk
    • Elastic
    • Datadog
  • Access points

    Mixed estates are supported.
    • Cisco Meraki
    • HPE Aruba
    • Ruckus
    • Juniper Mist
    • Ubiquiti UniFi
    • Cambium
    • Extreme
    • Fortinet

Proof

Many organizations on shared infrastructure

Vancouver International Airport and Kinetic Melbourne Airport put every concession on its own keys, which is the model a lot runs for productions.

Vancouver
International Airport runs on Purple, concessions on their own keys
Melbourne
Kinetic Melbourne Airport runs on Purple, concessions on their own keys
80,000+
venues run on Purple, in 90 countries

FAQ

Questions IT leads ask

Do we need new access points on the lot?

No. Purple Access is a cloud overlay on the access points your lot already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.

Is a production's network really private?

Each production is its own VLAN or role with client isolation by default, returned by RADIUS at authentication and enforced by your access points. What may cross to the studio's own systems is policy at your gateway.

What happens at wrap?

Every key carries the contract's end date. After it RADIUS rejects the key, and a CoA ends a live session on access points that support it. Revoking a whole production touches no other.

Does each production need its own SSID?

No. One xPSK SSID carries every production, and the VLAN comes back from RADIUS, so a new production adds keys and never beacons. 8 to 10 SSIDs use 15 to 25% of channel airtime.

How do visiting talent and agents get online without a key?

On the open network, through the captive portal, on a guest VLAN that shares nothing with a production.

Is xPSK the same as iPSK, PPSK, DPSK, MPSK or EasyPSK?

Yes. xPSK is our name for the capability each vendor ships under its own: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK. Purple runs all of them from one platform, on a mixed estate.

Book a demo: we issue and revoke a key on a live network

Bring a production's worth of kit: a crew phone, a monitor and a controller, from two productions. We issue each a key, place it on its production's VLAN and wrap one live.

  1. Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
  2. We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
  3. You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.

Your design session

Your live key demo

A Purple network engineer runs the demo with you, on your kind of estate.