Skip to content
Travel and venues: Hotels

Hotels: portal for guests, EAP-TLS for staff, a personal WiFi key per room device

Guests sign in on the portal with a PMS room check, and returning guests roam on Passpoint. Staff authenticate with EAP-TLS from your MDM, and every room TV, thermostat and register gets its own MAC-bound key and VLAN, all in one log.

  • Whitbread runs segmented staff WiFi on Purple
  • 80,000+ venues in 90 countries
  • 99.9% RADIUS uptime SLA
  • PMS room check

Phones, laptops, tills, CCTV and TVs join through your access point. Cloud RADIUS checks each one and sends it to the open, secure or xPSK network by identity, each on its own VLAN; a leaver whose account is disabled is rejected.

Every deviceYour access pointsCloud RADIUSRejected: account disabled
Open
  • Captive portal sign-in
  • Consent recorded
  • BYOD onboarding lane
Secure
  • EAP-TLS from your MDM
  • Identity decides the VLAN
  • Passpoint and OpenRoaming
xPSK
  • A key per device
  • Own VLAN and bandwidth limit
  • Revoke one key alone
VLAN 10VLAN 20VLAN 40
Book my design session

Who is on the hotels network

Who connects, and where each one lands

Three networks per property: guests on the portal with a PMS room check, staff on EAP-TLS or Passpoint, and room TVs, thermostats and registers on key-bound VLANs guests never see.

Who connects, and where each one lands
Who or what connectsNetworkAuthenticationPlacementWhat starts and ends access
GuestsOpenCaptive portal with a PMS room check (or SSO, social, SMS)Guest VLAN, client isolation onConsent recorded at sign-in, and the PMS check ties the session to a room
Returning, long-stay and VIP guestsSecurePasspoint or OpenRoaming profileGuest VLAN, with no portal on returnProfile installed once, valid at every property that runs it
Front desk, housekeeping and F&BSecureEAP-TLS, certificate from your MDM over SCEPVLAN by directory groupAccount disabled, and RADIUS CoA ends the session
ContractorsxPSKIndividual key, MAC-bound (time-limited, no MDM)A VLAN and bandwidth limit per keyEnds on its end date
Room TVs, thermostats, door controllers and CCTVxPSKIndividual key, MAC-boundA device VLAN per class, unreachable from guestsRevoked when the device is swapped
Registers, card terminals and back-office PCsxPSKIndividual key, MAC-boundPayments and back-office VLANs, apart from guestsOne key per device, rotated or revoked alone

Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.

Hotels: open, secure and xPSK

Three networks, each doing its own job

Identity decides the VLAN inside each network, so one SSID carries many groups.

Guests and staff phones: portal, PMS check, onboarding lane

The guest lane and the BYOD onboarding lane. Sign-in methods are your choice per property, and the PMS check ties a session to a room.

  • A room number against the PMS. The portal checks it before the session starts, with consent recorded for GDPR and CCPA.
  • Sign-in methods per brand. SSO, Google, Apple, Facebook, SMS or room number, and under 15 minutes to add the splash URL and RADIUS to a controller.
  • Staff phones with no MDM. Sign in once in the Purple app and a WiFi pass installs, on Windows, macOS, Linux, iOS and Android.
Illustration

Lifecycle

Key lifecycle: commission, place, operate, decommission

The same four moves serve a room TV and a leaver, tied to the systems you already run: your device register, your directory and your PMS.

Issue at commissioning

Key room devices at installation, from the console, in bulk from your device list or through the Purple API, each bound to the device's MAC.

Illustration

Place on a VLAN by device class

RADIUS returns the VLAN, role or group policy, depending on your vendor. Your access points enforce it and your gateway holds the inter-VLAN rules.

Illustration

Operate from one log

Every accept and reject carries its reason, by guest, staff member and device, across every property, streamed to your SIEM.

Illustration

End one key, or one leaver

Replace a TV and you revoke its key alone. Disable a leaver and the certificate stops being accepted, with RADIUS CoA ending the live session.

Illustration

One authentication log

One authentication log across every property

Guest sign-ins, staff certificates and room-device keys land in the same log, so "what is this device, and who is it for" is a query and not a site visit.

  • Which room devices are on the network at each property, and on which VLAN.
  • Which staff accounts authenticated today, by which method, and which were rejected and why.
  • Which guest sessions came through the portal, and which returned on Passpoint.
  • Whether a leaver's session ended with their account.
Illustration

Audit

Payments apart from guests: what your QSA tests against

Purple never touches card data. Segmentation hands your assessor a VLAN map and an authentication log to test against.

  • PCI DSS v4.0.1 Req 2.3.2

    Wireless keys must change when anyone who knows them leaves. A key per device makes that one rotation, not every register.
  • PCI DSS Req 8 and 10

    Every authentication is logged with the identity and the reason, and streamed to your SIEM as evidence.

Works with

Your directory, your MDM, your SIEM, your access points

Nothing is replaced. Purple Access sits on the systems your team already runs.

  • Identity providers

    Over SAML and SCIM. Group membership decides the VLAN.
    • Microsoft Entra ID
    • Okta
    • Google Workspace
  • Device management

    EAP-TLS certificates delivered over SCEP, with a compliance-gated join.
    • Microsoft Intune
    • Jamf Pro
    • JumpCloud
    • Kandji
    • Hexnode
    • Iru
    • Addigy
  • SIEM

    The authentication log, over webhook or syslog.
    • Microsoft Sentinel
    • Splunk
    • Elastic
    • Datadog
  • Access points

    Mixed estates are supported.
    • Cisco Meraki
    • HPE Aruba
    • Ruckus
    • Juniper Mist
    • Ubiquiti UniFi
    • Cambium
    • Extreme
    • Fortinet

Proof

Hotel groups run on it

Whitbread
runs segmented staff WiFi on Purple
80,000+
venues run on Purple, in 90 countries
500M
logins a year
99.9%
cloud RADIUS uptime SLA, in your contract

Add-on: Purple Shield

Add protective DNS with Purple Shield

Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.

Illustration

FAQ

Questions IT leads ask

Can guests sign in with a room number?

Yes. The captive portal checks the room number against your property management system, or guests can use SSO, social or SMS.

Do we need new access points in our hotels?

No. Purple Access is a cloud overlay on the access points your hotels already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.

How does a room TV with no browser and no supplicant get on?

To the TV, its xPSK key is an ordinary WPA2-Personal passphrase, so there is no supplicant and no portal. The per-device key lives on the access point side, under each vendor's name for it (Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK).

Does xPSK take our WiFi out of PCI scope?

Purple never touches payment card data. Each register and card machine sits on its own key and its own VLAN, apart from guests and staff, and every authentication is logged as evidence for PCI DSS Req 8 and 10. We hand your QSA the VLAN map and the authentication log to test against.

What happens to a leaver's access?

Their account is disabled once in the organization's Entra ID, Okta or Google Workspace. Cloud RADIUS rejects the next authentication, and RADIUS CoA ends the live session on access points that support it.

Book a demo: we issue and revoke a key on a live network

Bring a room's worth of devices: a TV, a thermostat, a register and a staff phone. We issue each a key or a certificate, place it on its VLAN and revoke one live, on the access points you already run.

  1. Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
  2. We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
  3. You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.

Your design session

Your live key demo

A Purple network engineer runs the demo with you, on your kind of estate.