Hotels: portal for guests, EAP-TLS for staff, a personal WiFi key per room device
Guests sign in on the portal with a PMS room check, and returning guests roam on Passpoint. Staff authenticate with EAP-TLS from your MDM, and every room TV, thermostat and register gets its own MAC-bound key and VLAN, all in one log.
- Whitbread runs segmented staff WiFi on Purple
- 80,000+ venues in 90 countries
- 99.9% RADIUS uptime SLA
- PMS room check
Phones, laptops, tills, CCTV and TVs join through your access point. Cloud RADIUS checks each one and sends it to the open, secure or xPSK network by identity, each on its own VLAN; a leaver whose account is disabled is rejected.
Who is on the hotels network
Who connects, and where each one lands
Three networks per property: guests on the portal with a PMS room check, staff on EAP-TLS or Passpoint, and room TVs, thermostats and registers on key-bound VLANs guests never see.
| Who or what connects | Network | Authentication | Placement | What starts and ends access |
|---|---|---|---|---|
| Guests | Open | Captive portal with a PMS room check (or SSO, social, SMS) | Guest VLAN, client isolation on | Consent recorded at sign-in, and the PMS check ties the session to a room |
| Returning, long-stay and VIP guests | Secure | Passpoint or OpenRoaming profile | Guest VLAN, with no portal on return | Profile installed once, valid at every property that runs it |
| Front desk, housekeeping and F&B | Secure | EAP-TLS, certificate from your MDM over SCEP | VLAN by directory group | Account disabled, and RADIUS CoA ends the session |
| Contractors | xPSK | Individual key, MAC-bound (time-limited, no MDM) | A VLAN and bandwidth limit per key | Ends on its end date |
| Room TVs, thermostats, door controllers and CCTV | xPSK | Individual key, MAC-bound | A device VLAN per class, unreachable from guests | Revoked when the device is swapped |
| Registers, card terminals and back-office PCs | xPSK | Individual key, MAC-bound | Payments and back-office VLANs, apart from guests | One key per device, rotated or revoked alone |
Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.
Hotels: open, secure and xPSK
Three networks, each doing its own job
Identity decides the VLAN inside each network, so one SSID carries many groups.
Guests and staff phones: portal, PMS check, onboarding lane
The guest lane and the BYOD onboarding lane. Sign-in methods are your choice per property, and the PMS check ties a session to a room.
- A room number against the PMS. The portal checks it before the session starts, with consent recorded for GDPR and CCPA.
- Sign-in methods per brand. SSO, Google, Apple, Facebook, SMS or room number, and under 15 minutes to add the splash URL and RADIUS to a controller.
- Staff phones with no MDM. Sign in once in the Purple app and a WiFi pass installs, on Windows, macOS, Linux, iOS and Android.
Staff and returning guests: EAP-TLS and Passpoint
One WPA-Enterprise SSID. Cloud RADIUS checks the directory and returns the VLAN for the group, so each team lands in its own lane.
- EAP-TLS from your MDM. Microsoft Intune, Jamf Pro, JumpCloud, Kandji, Hexnode, Iru and Addigy deliver the certificate over SCEP. Setup is five to ten minutes, once.
- Directory groups decide the VLAN. Entra ID, Okta or Google Workspace over SAML and SCIM. Disable a leaver once and every property stops authenticating them.
- Passpoint for returning guests. Install a profile once and join every property that runs it, with OpenRoaming free on the Connect license.
Room devices and back of house: a key each, on its own VLAN
Anything with no 802.1X supplicant, screen or certificate store gets its own key on one SSID. MAC binding stops a key becoming a second shared password.
- Room TVs, thermostats and door controllers. Each on a MAC-bound key and a device VLAN the guest network cannot reach.
- Registers and card terminals. A key and a payments VLAN per device. Purple never touches card data.
- Contractors with nothing to install. A time-limited key from the portal or the Purple API, ending on the day the job does.
- A private network for long-stay guests. A long-stay guest gets a private network of their own: their Chromecast and console find each other.
Lifecycle
Key lifecycle: commission, place, operate, decommission
The same four moves serve a room TV and a leaver, tied to the systems you already run: your device register, your directory and your PMS.
Issue at commissioning
Key room devices at installation, from the console, in bulk from your device list or through the Purple API, each bound to the device's MAC.
Place on a VLAN by device class
RADIUS returns the VLAN, role or group policy, depending on your vendor. Your access points enforce it and your gateway holds the inter-VLAN rules.
Operate from one log
Every accept and reject carries its reason, by guest, staff member and device, across every property, streamed to your SIEM.
End one key, or one leaver
Replace a TV and you revoke its key alone. Disable a leaver and the certificate stops being accepted, with RADIUS CoA ending the live session.
One authentication log
One authentication log across every property
Guest sign-ins, staff certificates and room-device keys land in the same log, so "what is this device, and who is it for" is a query and not a site visit.
- Which room devices are on the network at each property, and on which VLAN.
- Which staff accounts authenticated today, by which method, and which were rejected and why.
- Which guest sessions came through the portal, and which returned on Passpoint.
- Whether a leaver's session ended with their account.
Audit
Payments apart from guests: what your QSA tests against
Purple never touches card data. Segmentation hands your assessor a VLAN map and an authentication log to test against.
PCI DSS v4.0.1 Req 2.3.2
Wireless keys must change when anyone who knows them leaves. A key per device makes that one rotation, not every register.PCI DSS Req 8 and 10
Every authentication is logged with the identity and the reason, and streamed to your SIEM as evidence.
Works with
Your directory, your MDM, your SIEM, your access points
Nothing is replaced. Purple Access sits on the systems your team already runs.
Identity providers
Over SAML and SCIM. Group membership decides the VLAN.- Microsoft Entra ID
- Okta
- Google Workspace
Device management
EAP-TLS certificates delivered over SCEP, with a compliance-gated join.- Microsoft Intune
- Jamf Pro
- JumpCloud
- Kandji
- Hexnode
- Iru
- Addigy
SIEM
The authentication log, over webhook or syslog.- Microsoft Sentinel
- Splunk
- Elastic
- Datadog
Access points
Mixed estates are supported.- Cisco Meraki
- HPE Aruba
- Ruckus
- Juniper Mist
- Ubiquiti UniFi
- Cambium
- Extreme
- Fortinet
Identity providers: setup and mappingDevice management: setup and mappingSIEM: setup and mappingHardware setup by vendor
Proof
Hotel groups run on it
- Whitbread
- runs segmented staff WiFi on Purple
- 80,000+
- venues run on Purple, in 90 countries
- 500M
- logins a year
- 99.9%
- cloud RADIUS uptime SLA, in your contract
Add-on: Purple Shield
Add protective DNS with Purple Shield
Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.
FAQ
Questions IT leads ask
Can guests sign in with a room number?
Yes. The captive portal checks the room number against your property management system, or guests can use SSO, social or SMS.
Do we need new access points in our hotels?
No. Purple Access is a cloud overlay on the access points your hotels already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.
How does a room TV with no browser and no supplicant get on?
To the TV, its xPSK key is an ordinary WPA2-Personal passphrase, so there is no supplicant and no portal. The per-device key lives on the access point side, under each vendor's name for it (Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK).
Does xPSK take our WiFi out of PCI scope?
Purple never touches payment card data. Each register and card machine sits on its own key and its own VLAN, apart from guests and staff, and every authentication is logged as evidence for PCI DSS Req 8 and 10. We hand your QSA the VLAN map and the authentication log to test against.
What happens to a leaver's access?
Their account is disabled once in the organization's Entra ID, Okta or Google Workspace. Cloud RADIUS rejects the next authentication, and RADIUS CoA ends the live session on access points that support it.
Book a demo: we issue and revoke a key on a live network
Bring a room's worth of devices: a TV, a thermostat, a register and a staff phone. We issue each a key or a certificate, place it on its VLAN and revoke one live, on the access points you already run.
- Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
- We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
- You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.
Your design session
Your live key demo
A Purple network engineer runs the demo with you, on your kind of estate.