Skip to content
Residential: Multifamily and apartments

Multifamily: a personal WiFi key per household, staff on EAP-TLS, visitors on the portal

Bulk internet delivered as managed, home-like WiFi in every unit: one xPSK SSID per community, one key and VLAN per household, and the same model on whichever access points each acquisition came with. Staff sign in on EAP-TLS and visitors use the portal, all in one log.

  • 80,000+ venues in 90 countries
  • 1,000+ connectors
  • 99.9% RADIUS uptime SLA
Illustration
Illustration: one xPSK SSID with a unique key per device, resident, tenant and contractor, each on its own VLAN and bandwidth limit, revocable on its own.
Book my design session

Who is on the multifamily and apartments network

Who connects in a multifamily (MDU) apartment community, and where each one lands

Bulk internet delivered per unit across a mixed access point estate: the unit is a VLAN or role and not an SSID or a router, with one RADIUS and one dashboard across the portfolio, on any AP brand.

Who connects in a multifamily (MDU) apartment community, and where each one lands
Who or what connectsNetworkAuthenticationPlacementWhat starts and ends access
Prospects and visitors in the leasing office and clubhouseOpenCaptive portal sign-in, consent recorded (or SSO, social, SMS)Guest VLAN, client isolation onConsent recorded at sign-in, session expires on timeout
Maintenance staff on personal phonesOpenPurple app onboarding, certificate installed, no MDMOnboarding lane, then the group VLANEnds with the directory account
Leasing and maintenance staff on managed devicesSecureEAP-TLS, certificate from your MDM over SCEPVLAN by directory group, per communityAccount disabled, and RADIUS CoA ends the session
Regional and portfolio managersSecurePasspoint or OpenRoaming profile (or EAP-TLS)A management VLAN at every community they coverProfile installed once, valid wherever the platform runs
Leaseholders and their householdsxPSKIndividual key, MAC-bound (one key per household)A VLAN or role per unit, with its own bandwidth limitIssued at lease signing, revoked at move-out
Property-owned devices: access control, cameras, leasing-office printersxPSKIndividual key, MAC-bound (bound to the device's MAC)A building-systems VLAN, unreachable from unitsOne key per device, revoked when the device is swapped
Vendors: cleaners, pest control, HVAC and repair crewsxPSKIndividual key, MAC-bound (time-limited, no MDM)A vendor VLAN and bandwidth limit per keyEnds on the day the work order does

Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.

Multifamily and apartments: open, secure and xPSK

Three networks, each doing its own job

Identity decides the VLAN inside each network, so one SSID carries many groups.

Prospects, visitors and staff phones: portal and onboarding lane

The public lane for the leasing office and clubhouse, and the onboarding lane for staff whose phones the property does not manage.

  • A portal per community. Sign-in methods and branding per property, with consent recorded for GDPR and CCPA. Under 15 minutes to add the splash URL and RADIUS to a controller.
  • Maintenance phones with no MDM. Sign in once in the Purple app and a WiFi pass installs, on Windows, macOS, Linux, iOS and Android, then the phone lands on its group VLAN.
Illustration

Lifecycle

Lease-up, occupancy, turnover: one key lifecycle per household

Multifamily turns over in waves, with a lease-up at opening and a rolling cycle after. The same four moves handle both, tied to your lease list and your directory.

Issue in bulk at lease-up

Create a community's household keys from the lease list when it opens, then one at a time as leases sign, from the console or through the Purple API. Property devices are keyed once, at commissioning.

Illustration

Place each unit on its own VLAN

RADIUS returns the VLAN, role or group policy, depending on each community's vendor, with a bandwidth limit per key. The access points enforce it, and rules between VLANs live on your gateway.

Illustration

Operate the portfolio from one log

Every accept and reject carries its reason, by community, unit and device, whichever access point brand answered, streamed to Microsoft Sentinel, Splunk, Elastic or Datadog.

Illustration

Revoke at turnover, not at the building

A move-out withdraws one key and ends its live session with RADIUS CoA on access points that support it. Neighboring units and the property's own devices keep their keys.

Illustration

One authentication log

One authentication log across communities and AP brands

Acquisitions rarely share a controller vendor, so per-controller logs mean five consoles and no portfolio view. One RADIUS gives one record, whichever access point answered.

  • Which units authenticated in the last day at each community, and on which VLAN.
  • Which property devices are authenticating, and which have dropped off since last week.
  • Why a resident's device was rejected: a revoked key, an expired key or an unbound MAC address.
  • Which vendor keys are still live after their work order closed.
  • How authentication volume compares across communities on different AP brands.
Illustration

Works with

Your directory, your MDM, your SIEM, your access points

Nothing is replaced. Purple Access sits on the systems your team already runs.

  • Identity providers

    Over SAML and SCIM. Group membership decides the VLAN.
    • Microsoft Entra ID
    • Okta
    • Google Workspace
  • Device management

    EAP-TLS certificates delivered over SCEP, with a compliance-gated join.
    • Microsoft Intune
    • Jamf Pro
    • JumpCloud
    • Kandji
    • Hexnode
    • Iru
    • Addigy
  • SIEM

    The authentication log, over webhook or syslog.
    • Microsoft Sentinel
    • Splunk
    • Elastic
    • Datadog
  • Access points

    Mixed estates are supported.
    • Cisco Meraki
    • HPE Aruba
    • Ruckus
    • Juniper Mist
    • Ubiquiti UniFi
    • Cambium
    • Extreme
    • Fortinet

Proof

A platform built for estates, not single sites

About 1 million students and residents run on Purple's community networks, and every community on the platform reports into the same log.

80,000+
venues run on Purple, in 90 countries
~1M
students and residents on Purple community networks
1,000+
connectors to the tools you already run
99.9%
cloud RADIUS uptime SLA, in your contract

Add-on: Purple Shield

Add protective DNS with Purple Shield

Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.

Illustration

FAQ

Questions IT leads ask

Do we need to standardize on one access point brand?

No. Purple Access is a cloud overlay on the access points your communities already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.

Is xPSK one SSID or one per household, tenant or device?

One SSID. Every key on it has its own VLAN, policy and bandwidth limit, returned by RADIUS at authentication, and there is no per-SSID key ceiling. Adding a key never adds a beacon.

Is xPSK the same as iPSK, PPSK, DPSK, MPSK or EasyPSK?

Yes. xPSK is our name for the capability each vendor ships under its own: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK. Purple runs all of them from one platform, on a mixed estate.

We acquired communities on Meraki, Aruba and Ruckus. Is that one platform?

Yes. Each vendor's per-device key feature has its own name and its own RADIUS attributes, and Purple runs all of them from one platform. The unit's VLAN or role is returned in the form each vendor expects, so the portfolio keeps one RADIUS, one dashboard and one log.

What stops one unit reaching another's devices?

Each household's key returns its own VLAN or role with client isolation on, so the access points never bridge one unit to another. Any exception, such as a shared printer in the leasing office, is a rule you write at the gateway.

What stops a resident passing their key to the next unit?

MAC binding ties the key to the household's devices, so a copied key fails on a device it was not bound to. It is strongest on fixed-MAC devices such as TVs and sensors, and the log shows every rejection with its reason.

Book a demo: we issue and revoke a key on a live network

Bring two communities on different access point brands. We issue a household key at each, place it on its unit VLAN, revoke one live and show you the single log both land in.

  1. Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
  2. We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
  3. You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.

Your design session

Your live key demo

A Purple network engineer runs the demo with you, on your kind of estate.