Skip to content
Work and commercial: Multi-tenant office buildings

Multi-tenant offices: visitors on the portal, staff on EAP-TLS, a VLAN and personal WiFi keys per tenant

The landlord runs the access points and the uplink once. RADIUS returns a VLAN or role per tenant, tenant staff authenticate through their own directory, visitors sign in on the portal, and every building system gets a personal WiFi key on its own VLAN.

  • Vancouver International Airport
  • Kinetic Melbourne Airport
  • 80,000+ venues in 90 countries
  • 99.9% RADIUS uptime SLA

Phones, laptops, tills, CCTV and TVs join through your access point. Cloud RADIUS checks each one and sends it to the open, secure or xPSK network by identity, each on its own VLAN; a leaver whose account is disabled is rejected.

Every deviceYour access pointsCloud RADIUSRejected: account disabled
Open
  • Captive portal sign-in
  • Consent recorded
  • BYOD onboarding lane
Secure
  • EAP-TLS from your MDM
  • Identity decides the VLAN
  • Passpoint and OpenRoaming
xPSK
  • A key per device
  • Own VLAN and bandwidth limit
  • Revoke one key alone
VLAN 10VLAN 20VLAN 40
Book my design session

Who is on the multi-tenant office buildings network

Who connects, and where each one lands

The landlord owns the radios and the uplink and each tenant owns its identity: a VLAN or role per tenant on the landlord's access points, with building systems such as HVAC and access control in a lane of their own.

Who connects, and where each one lands
Who or what connectsNetworkAuthenticationPlacementWhat starts and ends access
Visitors and lobby guestsOpenCaptive portal sign-in, consent recordedGuest VLAN, client isolation onConsent recorded at sign-in
Tenant staff on laptops and phonesOpenPurple app onboarding, certificate installed, no MDM (signed in with the tenant's own account)Onboarding lane, then the tenant's VLAN or role by directory groupEnds when the account is disabled in the tenant's directory
Landlord and building management teamSecureEAP-TLS, certificate from your MDM over SCEPManagement VLAN by directory groupAccount disabled, and RADIUS CoA ends the session
Returning visitors and regular tenant staffSecurePasspoint or OpenRoaming profileGuest or tenant VLAN, with no portal on returnProfile installed once, valid at every building that runs it
Tenant printers, screens and meeting-room kitxPSKIndividual key, MAC-boundThe tenant's VLAN or role, a key per deviceRevoked when the device is swapped or the tenant leaves
Visitors whose kit cannot do a portalxPSKIndividual key, MAC-bound (issued at reception sign-in)A visitor VLAN with a bandwidth limitEnds on its end date
HVAC, access control, elevators and meteringxPSKIndividual key, MAC-boundA building-systems VLAN apart from every tenantRevoked when the controller is replaced
Cleaning, security and maintenance contractorsxPSKIndividual key, MAC-bound (time-limited, no MDM)A VLAN and bandwidth limit per keyEnds on its end date

Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.

Multi-tenant office buildings: open, secure and xPSK

Three networks, each doing its own job

Identity decides the VLAN inside each network, so one SSID carries many groups.

Visitors and tenant staff: portal and onboarding lane

The guest lane and the BYOD onboarding lane, shared by every tenant on the building's access points.

  • One portal for the building. Visitors sign in with SSO, Google, Apple or SMS, and consent is recorded for GDPR and CCPA. The splash URL and RADIUS go onto a controller in under 15 minutes.
  • Visitors apart from every tenant. Access points place portal guests on a guest-only VLAN with client isolation on, so a visitor in the lobby never sees a tenant's printer.
  • Tenant staff with no MDM. Staff sign in once in the Purple app with their company's Microsoft, Google or Okta account and a certificate-backed WiFi pass installs, on Windows, macOS, Linux, iOS and Android.
Illustration

Lifecycle

Key lifecycle: onboard a tenant, key its kit, hand back the floor

The unit is the tenant. The systems of record are your lease schedule and the tenant's own directory.

Create the tenant once

A tenant is one entry in the landlord's dashboard. Its staff come in through its directory, and its devices are keyed from the console, in bulk from a list or through the Purple API, each bound to its MAC address.

Illustration

Place the tenant on a VLAN or role

RADIUS returns the tenant's VLAN, role or group policy and a bandwidth limit, depending on your vendor. Your access points enforce it, and a shared-service rule, such as a floor printer, lives on your gateway.

Illustration

Operate from one landlord dashboard

Every accept and reject carries the tenant, the method and the reason, across every floor and building, and streams to Microsoft Sentinel, Splunk, Elastic or Datadog.

Illustration

Hand back the floor

When a lease ends, revoke the tenant's keys and nobody else is touched. RADIUS CoA ends live sessions on access points that support it, and the next tenant starts from a clean key set.

Illustration

One authentication log

One landlord log across every tenant and building

Tenant staff, visitors, contractors and building controllers land in one log, so "whose device is this" is a query and a tenant's separation is something you can show.

  • Which tenant each device belongs to, and which keys are still live after a lease has ended.
  • Which building systems are on the network, and on which VLAN.
  • Whether a tenant's leaver was rejected after the tenant disabled the account in its own directory.
  • How many visitors came through the portal, by building and hour.
Illustration

Audit

What a tenant's security team asks the landlord for

A tenant's IT team asks the landlord to show that other tenants cannot reach it. The VLAN or role map and the authentication log are that answer.

  • ISO 27001 and Cyber Essentials Plus

    Held by Purple, for the supplier section of a tenant's security review.
  • Evidence of separation

    A VLAN or role per tenant and one authentication log: the pair a tenant's IT team asks for before signing.

Works with

Your directory, your MDM, your SIEM, your access points

Nothing is replaced. Purple Access sits on the systems your team already runs.

  • Identity providers

    Over SAML and SCIM. Group membership decides the VLAN.
    • Microsoft Entra ID
    • Okta
    • Google Workspace
  • Device management

    EAP-TLS certificates delivered over SCEP, with a compliance-gated join.
    • Microsoft Intune
    • Jamf Pro
    • JumpCloud
    • Kandji
    • Hexnode
    • Iru
    • Addigy
  • SIEM

    The authentication log, over webhook or syslog.
    • Microsoft Sentinel
    • Splunk
    • Elastic
    • Datadog
  • Access points

    Mixed estates are supported.
    • Cisco Meraki
    • HPE Aruba
    • Ruckus
    • Juniper Mist
    • Ubiquiti UniFi
    • Cambium
    • Extreme
    • Fortinet

Proof

Many organizations on one set of radios, live at airports

Vancouver International Airport and Kinetic Melbourne Airport run concessions on their own keys, the same design a building uses for its tenants.

Vancouver
International Airport runs on Purple, concessions on their own keys
Melbourne
Kinetic Melbourne Airport runs on Purple, concessions on their own keys
80,000+
venues run on Purple, in 90 countries
99.9%
cloud RADIUS uptime SLA, in your contract

Add-on: Purple Shield

Add protective DNS with Purple Shield

Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.

Illustration

FAQ

Questions IT leads ask

Is xPSK the same as iPSK, PPSK, DPSK, MPSK or EasyPSK?

Yes. xPSK is our name for the capability each vendor ships under its own: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK. Purple runs all of them from one platform, on a mixed estate.

Do we need new access points?

No. Purple Access is a cloud overlay on the access points your buildings already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.

Who owns what in a multi-tenant building?

The landlord owns the radios and the uplink, and each tenant owns its identity. One platform returns a VLAN or role per tenant, and a tenant on Entra ID, Okta or Google Workspace uses it behind its own staff WiFi.

Does each tenant need its own SSID?

No. One xPSK SSID carries every key, and RADIUS returns the tenant's VLAN or role at authentication. 8 to 10 SSIDs use 15 to 25% of channel airtime, which is why an SSID per tenant does not scale.

How are HVAC, access control and elevators kept away from tenants?

Each controller has its own MAC-bound key and sits on a building-systems VLAN. RADIUS returns the VLAN, your access points place the client, and your gateway holds the inter-VLAN rules, so no tenant reaches those systems by policy.

How do visitors get on without a key from IT?

Most use the portal. A visitor whose kit cannot complete a portal gets a time-limited key issued when they sign in at reception, from the console or the Purple API.

What does revoking one key do to everyone else?

Nothing. Each key is its own entry in RADIUS, bound to its device by MAC, so withdrawing one ends that device's access and leaves every other key connected. A live session is ended with RADIUS CoA on access points that support it.

Book a demo: we issue and revoke a key on a live network

Bring one tenant's worth of kit: a laptop, a printer, a visitor and a building controller. We issue each a key or a certificate, place it on its VLAN and revoke one live, on the access points you already run.

  1. Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
  2. We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
  3. You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.

Your design session

Your live key demo

A Purple network engineer runs the demo with you, on your kind of estate.