Military family housing: a personal WiFi key per home, housing staff on EAP-TLS, visitors on the portal
Each service family gets one xPSK key and its own VLAN or role, issued in bulk ahead of the posting. Housing staff sign in on EAP-TLS, visitors use the portal, and estate systems keep their own keys, on the access points you already own.
- 80,000+ venues in 90 countries
- ISO 27001 and Cyber Essentials Plus
- 99.9% RADIUS uptime SLA
Who is on the military and service family housing network
Who connects on a service family accommodation estate, and where each one lands
A posting is a lifecycle event at estate scale: households arrive and leave in batches, so each home is a VLAN and a key issued and revoked in bulk from the allocation list.
| Who or what connects | Network | Authentication | Placement | What starts and ends access |
|---|---|---|---|---|
| Housing staff on personal phones | Open | Purple app onboarding, certificate installed, no MDM | Onboarding lane, then the group VLAN | Ends with the directory account |
| Visiting family and groups in community halls | Open | Captive portal sign-in, consent recorded (or SSO, social, SMS) | Guest VLAN, client isolation on | Consent recorded at sign-in, session expires on timeout |
| Housing office and welfare staff on managed devices | Secure | EAP-TLS, certificate from your MDM over SCEP | VLAN by directory group | Account disabled, and RADIUS CoA ends the session |
| Service families, home by home | xPSK | Individual key, MAC-bound (one key per home) | A VLAN or role per home, with client isolation on | Issued ahead of arrival, revoked at departure |
| Estate entry barriers, CCTV and street-lighting controllers | xPSK | Individual key, MAC-bound (bound to the device's MAC) | An estate-systems VLAN, unreachable from homes | One key per device, revoked when the device is swapped |
| Maintenance contractors | xPSK | Individual key, MAC-bound (time-limited, no MDM) | A contractor VLAN and bandwidth limit per key | Ends on the day the job does |
Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.
Military and service family housing: open, secure and xPSK
Three networks, each doing its own job
Identity decides the VLAN inside each network, so one SSID carries many groups.
Visitors, community halls and staff phones: portal and onboarding lane
Everyone who is not a resident of a home or a member of the housing team gets the guest lane, and never a family's VLAN.
- Community halls and welfare centers on the portal. Sign-in by SSO, Google, Apple, Facebook or SMS, with consent recorded for GDPR and CCPA and client isolation on. Under 15 minutes to add the splash URL and RADIUS to a controller.
- Staff phones with no MDM. Sign in once in the Purple app and a WiFi pass installs, on Windows, macOS, Linux, iOS and Android, then the phone lands on its group VLAN.
Housing and welfare staff: EAP-TLS and directory groups
One WPA-Enterprise SSID per estate. Cloud RADIUS checks the directory and returns the VLAN for the group, so housing, maintenance and welfare each land in their own lane.
- EAP-TLS from your MDM. Microsoft Intune, Jamf Pro, JumpCloud, Kandji, Hexnode, Iru and Addigy deliver the certificate over SCEP. Setup is five to ten minutes, once, for the whole organization.
- Directory groups decide the VLAN. Entra ID, Okta or Google Workspace over SAML and SCIM. Disable a leaver once and every estate stops authenticating them.
Homes and estate systems: a key each, on its own VLAN
Every home is a separate trust boundary and every estate device is another. One xPSK SSID carries all of them, and an arrival or a departure is a key issued or withdrawn.
- WiFi ready on arrival at a new posting. Issue the incoming household's key from the allocation list before the move, so the home is online when the family opens the door and there is no broadband order to place.
- Each home sealed off from every other. Each key returns its own VLAN or role with client isolation on, so no home's devices are visible to another's. It is enforced by your access points as policy, and exceptions are gateway rules you write.
- Estate systems on their own keys. Barriers, cameras and lighting controllers sit on an estate-systems VLAN that homes cannot reach, and each is revoked alone when it is replaced.
- Contractors with nothing to install. A time-limited key from the self-service portal or the Purple API, ending on the day the job does.
Lifecycle
Posting in, posting out: one key per home per occupancy
The system of record is your housing allocation list. Arrivals and departures cluster around posting dates, so the lifecycle is built to run in bulk.
Issue ahead of the posting
Create the incoming families' keys from the allocation list before the move, in bulk from the console or through the Purple API. Estate systems are keyed once, at commissioning.
Place each home on its own VLAN
RADIUS returns the VLAN, role or group policy, depending on each estate's vendor. The access points enforce it, and rules between VLANs live on your gateway.
Operate every estate from one log
Every accept and reject carries its reason, by estate, home and device, and streams to Microsoft Sentinel, Splunk, Elastic or Datadog.
Withdraw the departing key, in bulk if needed
A departure withdraws that home's key and ends its live session with RADIUS CoA on access points that support it. A batch of departures is the same action across a list, and no other home is touched.
One authentication log
One authentication log across every estate and posting cycle
Posting season is a spike in issuance and revocation. One log shows what was issued, what joined and what was withdrawn, estate by estate.
- Which homes' keys have never authenticated since arrival, estate by estate.
- Which keys were withdrawn at departure, and whether their live sessions ended.
- Why a device was rejected: a revoked key, an expired key or an unbound MAC address.
- Which estate systems are authenticating, and on which VLAN.
- Which contractor keys are still live after the job closed.
Works with
Your directory, your MDM, your SIEM, your access points
Nothing is replaced. Purple Access sits on the systems your team already runs.
Identity providers
Over SAML and SCIM. Group membership decides the VLAN.- Microsoft Entra ID
- Okta
- Google Workspace
Device management
EAP-TLS certificates delivered over SCEP, with a compliance-gated join.- Microsoft Intune
- Jamf Pro
- JumpCloud
- Kandji
- Hexnode
- Iru
- Addigy
SIEM
The authentication log, over webhook or syslog.- Microsoft Sentinel
- Splunk
- Elastic
- Datadog
Access points
Mixed estates are supported.- Cisco Meraki
- HPE Aruba
- Ruckus
- Juniper Mist
- Ubiquiti UniFi
- Cambium
- Extreme
- Fortinet
Identity providers: setup and mappingDevice management: setup and mappingSIEM: setup and mappingHardware setup by vendor
Proof
Platform assurance, in writing
Purple holds ISO 27001 and Cyber Essentials Plus, and the cloud RADIUS SLA is a floor we commit to in your contract.
- 80,000+
- venues run on Purple, in 90 countries
- 500M
- logins a year
- 99.9%
- cloud RADIUS uptime SLA, in your contract
- 99.999%
- uptime, with a 99.9% cloud RADIUS SLA and multi-region failover
Add-on: Purple Shield
Add protective DNS with Purple Shield
Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.
FAQ
Questions IT leads ask
Do we need new access points on our estates?
No. Purple Access is a cloud overlay on the access points your estates already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.
Is xPSK one SSID or one per household, tenant or device?
One SSID. Every key on it has its own VLAN, policy and bandwidth limit, returned by RADIUS at authentication, and there is no per-SSID key ceiling. Adding a key never adds a beacon.
Is xPSK the same as iPSK, PPSK, DPSK, MPSK or EasyPSK?
Yes. xPSK is our name for the capability each vendor ships under its own: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK. Purple runs all of them from one platform, on a mixed estate.
How can a home be online the day a family arrives?
The estate already has the uplink and the access points, so the only thing to issue is the family's key. Create it from the allocation list before the posting, and the first device to join authenticates on it with no account to set up and no engineer to send.
How do we handle a hundred departures and arrivals in one week?
Keys are created and withdrawn in bulk from a list, from the console or through the Purple API. Each withdrawal is one key, so a batch does not touch any home that is staying.
What does sealed off from every other home mean technically?
Each home's key returns its own VLAN or role with client isolation on, so devices on one home's VLAN cannot reach another's. That is policy enforced by the access points and your gateway, a logical boundary and not a physical one.
What assurance does Purple hold?
Purple holds ISO 27001 and Cyber Essentials Plus. The platform logs every authentication with its reason for your own assurance work, and it does not itself confer any accreditation on your estate.
Book a demo: we issue and revoke a key on a live network
Bring one estate's worth of devices: a family's phone, an entry barrier, a housing officer's laptop and a contractor's phone. We issue each a key or a certificate, place it on its VLAN and revoke one live, on the access points you already run.
- Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
- We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
- You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.
Your design session
Your live key demo
A Purple network engineer runs the demo with you, on your kind of estate.