Multi-tenant offices: visitors on the portal, staff on EAP-TLS, a VLAN and personal WiFi keys per tenant
The landlord runs the access points and the uplink once. RADIUS returns a VLAN or role per tenant, tenant staff authenticate through their own directory, visitors sign in on the portal, and every building system gets a personal WiFi key on its own VLAN.
- Vancouver International Airport
- Kinetic Melbourne Airport
- 80,000+ venues in 90 countries
- 99.9% RADIUS uptime SLA
Phones, laptops, tills, CCTV and TVs join through your access point. Cloud RADIUS checks each one and sends it to the open, secure or xPSK network by identity, each on its own VLAN; a leaver whose account is disabled is rejected.
Who is on the multi-tenant office buildings network
Who connects, and where each one lands
The landlord owns the radios and the uplink and each tenant owns its identity: a VLAN or role per tenant on the landlord's access points, with building systems such as HVAC and access control in a lane of their own.
| Who or what connects | Network | Authentication | Placement | What starts and ends access |
|---|---|---|---|---|
| Visitors and lobby guests | Open | Captive portal sign-in, consent recorded | Guest VLAN, client isolation on | Consent recorded at sign-in |
| Tenant staff on laptops and phones | Open | Purple app onboarding, certificate installed, no MDM (signed in with the tenant's own account) | Onboarding lane, then the tenant's VLAN or role by directory group | Ends when the account is disabled in the tenant's directory |
| Landlord and building management team | Secure | EAP-TLS, certificate from your MDM over SCEP | Management VLAN by directory group | Account disabled, and RADIUS CoA ends the session |
| Returning visitors and regular tenant staff | Secure | Passpoint or OpenRoaming profile | Guest or tenant VLAN, with no portal on return | Profile installed once, valid at every building that runs it |
| Tenant printers, screens and meeting-room kit | xPSK | Individual key, MAC-bound | The tenant's VLAN or role, a key per device | Revoked when the device is swapped or the tenant leaves |
| Visitors whose kit cannot do a portal | xPSK | Individual key, MAC-bound (issued at reception sign-in) | A visitor VLAN with a bandwidth limit | Ends on its end date |
| HVAC, access control, elevators and metering | xPSK | Individual key, MAC-bound | A building-systems VLAN apart from every tenant | Revoked when the controller is replaced |
| Cleaning, security and maintenance contractors | xPSK | Individual key, MAC-bound (time-limited, no MDM) | A VLAN and bandwidth limit per key | Ends on its end date |
Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.
Multi-tenant office buildings: open, secure and xPSK
Three networks, each doing its own job
Identity decides the VLAN inside each network, so one SSID carries many groups.
Visitors and tenant staff: portal and onboarding lane
The guest lane and the BYOD onboarding lane, shared by every tenant on the building's access points.
- One portal for the building. Visitors sign in with SSO, Google, Apple or SMS, and consent is recorded for GDPR and CCPA. The splash URL and RADIUS go onto a controller in under 15 minutes.
- Visitors apart from every tenant. Access points place portal guests on a guest-only VLAN with client isolation on, so a visitor in the lobby never sees a tenant's printer.
- Tenant staff with no MDM. Staff sign in once in the Purple app with their company's Microsoft, Google or Okta account and a certificate-backed WiFi pass installs, on Windows, macOS, Linux, iOS and Android.
Landlord team and tenant directories: EAP-TLS, groups and Passpoint
One WPA-Enterprise SSID. Cloud RADIUS checks the directory and returns the VLAN or role for the group, so each tenant lands in its own lane.
- EAP-TLS for the landlord's own fleet. Microsoft Intune, Jamf Pro, JumpCloud, Kandji, Hexnode, Iru and Addigy deliver the certificate over SCEP to the building team's devices. Setup is five to ten minutes, once.
- Each tenant's directory decides its VLAN. A tenant that runs Entra ID, Okta or Google Workspace uses it as the identity behind its own staff WiFi, over SAML and SCIM. Disable a leaver there and the pass stops authenticating.
- Passpoint for returning users. Install a profile once and rejoin automatically on every return, with OpenRoaming free through the Connect license.
Tenant kit, visitor keys, contractors and building systems
Anything with no 802.1X supplicant, no screen or no certificate store gets its own key on one SSID, placed in the lane that device belongs to.
- Tenant printers, screens and meeting-room kit. A MAC-bound key per device on the tenant's VLAN or role, issued in bulk from a device list or through the Purple API.
- Visitor keys at reception sign-in. A time-limited key issued from the console or the Purple API when the visitor signs in at reception, for visitors whose kit cannot complete a portal, such as a casting dongle or a demo unit.
- HVAC, access control and elevators kept apart. Each controller on its own MAC-bound key and a building-systems VLAN apart from every tenant. Inter-VLAN rules live on your gateway.
- Contractors with nothing to install. A time-limited key from the self-service portal or the Purple API, ending on the day the job does.
Lifecycle
Key lifecycle: onboard a tenant, key its kit, hand back the floor
The unit is the tenant. The systems of record are your lease schedule and the tenant's own directory.
Create the tenant once
A tenant is one entry in the landlord's dashboard. Its staff come in through its directory, and its devices are keyed from the console, in bulk from a list or through the Purple API, each bound to its MAC address.
Place the tenant on a VLAN or role
RADIUS returns the tenant's VLAN, role or group policy and a bandwidth limit, depending on your vendor. Your access points enforce it, and a shared-service rule, such as a floor printer, lives on your gateway.
Operate from one landlord dashboard
Every accept and reject carries the tenant, the method and the reason, across every floor and building, and streams to Microsoft Sentinel, Splunk, Elastic or Datadog.
Hand back the floor
When a lease ends, revoke the tenant's keys and nobody else is touched. RADIUS CoA ends live sessions on access points that support it, and the next tenant starts from a clean key set.
One authentication log
One landlord log across every tenant and building
Tenant staff, visitors, contractors and building controllers land in one log, so "whose device is this" is a query and a tenant's separation is something you can show.
- Which tenant each device belongs to, and which keys are still live after a lease has ended.
- Which building systems are on the network, and on which VLAN.
- Whether a tenant's leaver was rejected after the tenant disabled the account in its own directory.
- How many visitors came through the portal, by building and hour.
Audit
What a tenant's security team asks the landlord for
A tenant's IT team asks the landlord to show that other tenants cannot reach it. The VLAN or role map and the authentication log are that answer.
ISO 27001 and Cyber Essentials Plus
Held by Purple, for the supplier section of a tenant's security review.Evidence of separation
A VLAN or role per tenant and one authentication log: the pair a tenant's IT team asks for before signing.
Works with
Your directory, your MDM, your SIEM, your access points
Nothing is replaced. Purple Access sits on the systems your team already runs.
Identity providers
Over SAML and SCIM. Group membership decides the VLAN.- Microsoft Entra ID
- Okta
- Google Workspace
Device management
EAP-TLS certificates delivered over SCEP, with a compliance-gated join.- Microsoft Intune
- Jamf Pro
- JumpCloud
- Kandji
- Hexnode
- Iru
- Addigy
SIEM
The authentication log, over webhook or syslog.- Microsoft Sentinel
- Splunk
- Elastic
- Datadog
Access points
Mixed estates are supported.- Cisco Meraki
- HPE Aruba
- Ruckus
- Juniper Mist
- Ubiquiti UniFi
- Cambium
- Extreme
- Fortinet
Identity providers: setup and mappingDevice management: setup and mappingSIEM: setup and mappingHardware setup by vendor
Proof
Many organizations on one set of radios, live at airports
Vancouver International Airport and Kinetic Melbourne Airport run concessions on their own keys, the same design a building uses for its tenants.
- Vancouver
- International Airport runs on Purple, concessions on their own keys
- Melbourne
- Kinetic Melbourne Airport runs on Purple, concessions on their own keys
- 80,000+
- venues run on Purple, in 90 countries
- 99.9%
- cloud RADIUS uptime SLA, in your contract
Add-on: Purple Shield
Add protective DNS with Purple Shield
Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.
FAQ
Questions IT leads ask
Is xPSK the same as iPSK, PPSK, DPSK, MPSK or EasyPSK?
Yes. xPSK is our name for the capability each vendor ships under its own: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK. Purple runs all of them from one platform, on a mixed estate.
Do we need new access points?
No. Purple Access is a cloud overlay on the access points your buildings already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.
Who owns what in a multi-tenant building?
The landlord owns the radios and the uplink, and each tenant owns its identity. One platform returns a VLAN or role per tenant, and a tenant on Entra ID, Okta or Google Workspace uses it behind its own staff WiFi.
Does each tenant need its own SSID?
No. One xPSK SSID carries every key, and RADIUS returns the tenant's VLAN or role at authentication. 8 to 10 SSIDs use 15 to 25% of channel airtime, which is why an SSID per tenant does not scale.
How are HVAC, access control and elevators kept away from tenants?
Each controller has its own MAC-bound key and sits on a building-systems VLAN. RADIUS returns the VLAN, your access points place the client, and your gateway holds the inter-VLAN rules, so no tenant reaches those systems by policy.
How do visitors get on without a key from IT?
Most use the portal. A visitor whose kit cannot complete a portal gets a time-limited key issued when they sign in at reception, from the console or the Purple API.
What does revoking one key do to everyone else?
Nothing. Each key is its own entry in RADIUS, bound to its device by MAC, so withdrawing one ends that device's access and leaves every other key connected. A live session is ended with RADIUS CoA on access points that support it.
Book a demo: we issue and revoke a key on a live network
Bring one tenant's worth of kit: a laptop, a printer, a visitor and a building controller. We issue each a key or a certificate, place it on its VLAN and revoke one live, on the access points you already run.
- Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
- We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
- You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.
Your design session
Your live key demo
A Purple network engineer runs the demo with you, on your kind of estate.