Film and TV studios: visitors on the portal, staff on EAP-TLS, a personal WiFi key per crew member
Each production gets a private network on shared studio infrastructure, with keys timed to the production's contract. Studio operations sit on EAP-TLS, visiting talent and visitors use the portal, and one lot runs every shoot without building a network per shoot.
- 80,000+ venues in 90 countries
- 99.9% RADIUS uptime SLA
- 500 million logins a year
Who is on the film and tv studios network
Who and what connects on a lot, and where each one lands
Productions arrive, run for a contract's length and leave, and each needs its own VLAN on the lot's shared access points with keys that end when the contract does, so the studio never builds a network per shoot.
| Who or what connects | Network | Authentication | Placement | What starts and ends access |
|---|---|---|---|---|
| Studio staff on personal phones | Open | Purple app onboarding, certificate installed, no MDM | Onboarding lane, then the group VLAN | Ends with the directory account |
| Visiting talent, agents and drivers | Open | Captive portal sign-in, consent recorded | Guest VLAN, client isolation on | Consent recorded at sign-in, session ends on timeout |
| Studio operations and facilities staff | Secure | EAP-TLS, certificate from your MDM over SCEP | VLAN by directory group, apart from every production | Account disabled in the directory ends access |
| Post-production houses on the lot | Secure | EAP-TLS, certificate from your MDM over SCEP (the house's own directory and MDM) | The house's own VLAN or role | Ends when the house disables the account or the lease ends |
| Production crew | xPSK | Individual key, MAC-bound (from the crew list, time-limited to the contract) | The production's own VLAN | Ends on the wrap date set in the contract |
| On-set cameras, monitors and data carts | xPSK | Individual key, MAC-bound | The production's VLAN, apart from every other production | One key per device, revoked alone |
| Stage doors, lighting controllers and access control | xPSK | Individual key, MAC-bound | A studio-systems VLAN, apart from every production | One key per controller, revoked with the device |
| Set construction and facilities contractors | xPSK | Individual key, MAC-bound (time-limited, no MDM) | A contractor VLAN, crossings set at your gateway | Ends on the job's end date |
Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.
Film and TV studios: open, secure and xPSK
Three networks, each doing its own job
Identity decides the VLAN inside each network, so one SSID carries many groups.
Visiting talent and studio staff phones: portal and onboarding lane
Everyone who is on the lot for a day or is not on a production, on VLANs that share nothing with a production's network.
- Talent, agents and drivers on a portal. A captive portal records consent and lands the session on a guest VLAN with client isolation on, so a visitor's phone is never on a production's network.
- Studio staff phones with no MDM. Sign in once in the Purple app and a WiFi pass installs, then the phone moves to its group's VLAN.
- Every stage and office on one portal. Add the splash URL and RADIUS to the lot's controllers in under 15 minutes, on the access points already installed.
Studio operations and post-production houses: EAP-TLS and own directories
One WPA-Enterprise SSID. Each organization brings its own identity, and cloud RADIUS returns the VLAN for its group.
- EAP-TLS from your MDM. Microsoft Intune, Jamf Pro, JumpCloud, Kandji, Hexnode, Iru and Addigy deliver the certificate over SCEP. Setup is five to ten minutes, once, for the whole studio.
- Directory groups decide the VLAN. Studio operations, security and finance land on separate VLANs from Entra ID, Okta or Google Workspace groups.
- A post house signs in with its own directory. Each house on the lot federates its own Entra ID, Okta or Google Workspace, and its group lands on that house's VLAN.
Productions, crew and set kit: a key set per production
A production is the unit. Its crew and its devices hold keys that return the production's VLAN, and no other production shares a VLAN or a key with it.
- A private network per production. Create the production once and its crew and devices get keys that return its own VLAN or role. Another production on the same access points never shares either.
- Keys timed to the production's contract. Every key carries the wrap date as its end date, so access ends when the paperwork does and nobody collects a thing from the crew.
- The crew list in one import. A crew list becomes keys in one import, with a bandwidth limit per key so one camera card offload cannot crowd a stage.
- Separation for content security assessments. A VLAN map per production and the authentication log are what an assessor tests against: which keys, on which VLAN, authenticated and when.
Lifecycle
Production lifecycle: onboard, run, wrap, strike
The same four moves run for every production, tied to the paperwork a production already has: the contract, the crew list and the device list.
Issue from the contract and the crew list
Create the production, import the crew list and device list, or issue from the console or the Purple API. Each key is bound to its device's MAC address and carries the contract's wrap date.
Place on the production's VLAN
RADIUS returns the production's VLAN, role or group policy, depending on your vendor, plus the bandwidth limit. Your access points enforce it, and anything a production may reach in the studio's systems is policy at your gateway.
Operate from one log across every production
Every accept and reject carries the production, the key, the VLAN and the reason, so the lot answers which production, which device and why from one place.
Revoke at wrap, one production at a time
A production that wraps has its keys revoked in one pass and no other production is touched. RADIUS CoA ends live sessions on access points that support it.
One authentication log
One authentication log across every production on the lot
Crew keys, set kit, studio staff certificates and visitors land in the same log, tagged by production, so "who is on which shoot" is a query.
- Which productions are live on the lot and how many keys each has authenticated today.
- Which crew keys were rejected, with the VLAN they asked for and why.
- Whether any key from a wrapped production still authenticates.
- Which studio staff authenticated by EAP-TLS, and which post house they belong to.
Audit
Separation an assessor can test
Purple supplies the evidence: a VLAN map and a log per production, with the assessment itself run by the studio's client and its security vendor.
A VLAN map per production
Which keys belong to which production, and which VLAN each returns, exported for the assessor.The authentication log
Every accept and reject with the identity and the reason, streamed to your SIEM, so wrap and separation are shown and not asserted.
Works with
Your directory, your MDM, your SIEM, your access points
Nothing is replaced. Purple Access sits on the systems your team already runs.
Identity providers
Over SAML and SCIM. Group membership decides the VLAN.- Microsoft Entra ID
- Okta
- Google Workspace
Device management
EAP-TLS certificates delivered over SCEP, with a compliance-gated join.- Microsoft Intune
- Jamf Pro
- JumpCloud
- Kandji
- Hexnode
- Iru
- Addigy
SIEM
The authentication log, over webhook or syslog.- Microsoft Sentinel
- Splunk
- Elastic
- Datadog
Access points
Mixed estates are supported.- Cisco Meraki
- HPE Aruba
- Ruckus
- Juniper Mist
- Ubiquiti UniFi
- Cambium
- Extreme
- Fortinet
Identity providers: setup and mappingDevice management: setup and mappingSIEM: setup and mappingHardware setup by vendor
Proof
Many organizations on shared infrastructure
Vancouver International Airport and Kinetic Melbourne Airport put every concession on its own keys, which is the model a lot runs for productions.
- Vancouver
- International Airport runs on Purple, concessions on their own keys
- Melbourne
- Kinetic Melbourne Airport runs on Purple, concessions on their own keys
- 80,000+
- venues run on Purple, in 90 countries
FAQ
Questions IT leads ask
Do we need new access points on the lot?
No. Purple Access is a cloud overlay on the access points your lot already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.
Is a production's network really private?
Each production is its own VLAN or role with client isolation by default, returned by RADIUS at authentication and enforced by your access points. What may cross to the studio's own systems is policy at your gateway.
What happens at wrap?
Every key carries the contract's end date. After it RADIUS rejects the key, and a CoA ends a live session on access points that support it. Revoking a whole production touches no other.
Does each production need its own SSID?
No. One xPSK SSID carries every production, and the VLAN comes back from RADIUS, so a new production adds keys and never beacons. 8 to 10 SSIDs use 15 to 25% of channel airtime.
How do visiting talent and agents get online without a key?
On the open network, through the captive portal, on a guest VLAN that shares nothing with a production.
Is xPSK the same as iPSK, PPSK, DPSK, MPSK or EasyPSK?
Yes. xPSK is our name for the capability each vendor ships under its own: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK. Purple runs all of them from one platform, on a mixed estate.
Book a demo: we issue and revoke a key on a live network
Bring a production's worth of kit: a crew phone, a monitor and a controller, from two productions. We issue each a key, place it on its production's VLAN and wrap one live.
- Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
- We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
- You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.
Your design session
Your live key demo
A Purple network engineer runs the demo with you, on your kind of estate.