Retail WiFi: take the tills off the shared password
Shoppers on the captive portal, staff on certificates, tills, screens and CCTV each on their own key, and every concession in a mall on its own VLAN. McDonald's runs it with 80% fewer IT helpdesk requests. PCI DSS v4.0.1 Req 2.3.2 says wireless keys must change when anyone who knows them leaves.
- 80% fewer IT helpdesk requests at McDonald's
- on-site visits from IT engineers reduced by 90%
- 80,000+ venues
Your three networks
Three SSIDs for retail
Identity decides the VLAN inside each network, so one SSID carries many groups.
Network 1
Open
Shoppers sign in through the captive portal, with consent recorded for GDPR and CCPA.Network 2
Secure
Store and head office staff on EAP-TLS, with leavers revoked from the directory.Network 3
xPSK
A key per till, screen and camera, and a key and VLAN per concession in a mall.
IoT WiFi for tills, screens and camerasConcession WiFi for mall tenants
Visibility and reporting
Every authentication, store by store, in one place
Accepts and rejects with the reason, by member of staff, till and device, across every store, streamed to your SIEM and ready for the auditor.
- One estate-wide query, no per-building exports.
- Microsoft Sentinel, Splunk, Elastic or Datadog over webhook or syslog.
- Occupancy and footfall by site, hour and day, with MAC addresses anonymized.
Proof
Fewer tickets, fewer engineers on the road
- 80%
- fewer IT helpdesk requests at McDonald's
- 90%
- fewer on-site visits from IT engineers at McDonald's Belgium
On-site visits from IT engineers reduced by 90%.
Add-on: Purple Shield
Add protective DNS with Purple Shield
Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.
FAQ
Common questions
How does this help with PCI DSS?
With a key per device, rotating a key after a leaver means one device, not every till. Every authentication is logged for evidence against PCI DSS Req 8 and 10.
Do we need new access points in our stores?
No. Purple Access is a cloud overlay on the access points your stores already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet, and mixed estates are supported.
Does xPSK take our WiFi out of PCI scope?
Purple never touches payment card data. Each till and card machine sits on its own key and its own VLAN, apart from guests and staff, and every authentication is logged as evidence for PCI DSS Req 8 and 10. We hand your QSA the VLAN map and the authentication log to test against.
Will our tills and payment terminals work with a key each?
Yes. To a till, its xPSK key is an ordinary WPA2-Personal passphrase, so nothing on the till changes. The per-device key lives on the access point side, whether it is Cisco iPSK on Meraki or HPE Aruba MPSK, and Purple runs every vendor's version on one mixed estate.
What does rolling this out across hundreds of sites look like?
One site first, live in days, with your existing network running beside it. Then every other site gets the same three SSIDs from the same design, in waves you set. Each controller takes under 15 minutes to point at Purple. Managed devices pick up certificates from your MDM, and personal phones install a pass from the Purple app.
Get the tills off the guest network
Book a 45-minute design session and leave with the plan for your sites.
- Get your three-SSID plan in 45 minutesTell us what runs on your WiFi today, and a Purple network engineer maps it with you.
- Map your SSIDs onto threeOpen, secure and xPSK, on the access points you already own. You leave with the plan.
- Prove it on one site firstJudge the result on tickets and audit evidence, then roll out.
Your design session
45 minutes. Your estate. A plan you keep.
Led by a Purple network engineer. No slides. You keep the plan.