Skip to content
Education and public: Schools

Schools: visitors on the portal, directory groups for people, a personal WiFi key per display and substitute teacher

Staff and students authenticate against Google Workspace or Entra ID, with a VLAN per group. A substitute teacher gets a key for exactly the days booked, classroom displays and printers get MAC-bound device keys, and visitors use the portal.

  • 80,000+ venues in 90 countries
  • ISO 27001 and Cyber Essentials Plus
  • 99.9% RADIUS uptime SLA
  • 500 million logins a year
Illustration
Illustration: Entra ID, Okta and Google Workspace groups decide the VLAN for each certificate-based sign-in, and a leaver whose account is disabled is rejected with live sessions ended.
Book my design session

Who is on the schools network

Who connects in a school, and where each one lands

A school's cast changes weekly: temporary staff arrive for a day and leavers must vanish without a ticket. Access follows the directory and a calendar date, not a shared password, and classroom displays and printers sit on keys of their own.

Who connects in a school, and where each one lands
Who or what connectsNetworkAuthenticationPlacementWhat starts and ends access
Governors or board members, parents and event visitorsOpenCaptive portal sign-in, consent recordedGuest VLAN, client isolation onConsent recorded at sign-in, then the session times out
Staff and older students on personal devicesOpenPurple app onboarding, certificate installed, no MDM (school account)Onboarding lane, then the group VLANEnds with the directory account
Teachers and school staff on managed laptopsSecureEAP-TLS, certificate from your MDM over SCEP (from Intune or Jamf Pro)VLAN or role by directory groupAccount disabled once, and RADIUS CoA ends the session
Students on school-managed laptops and tabletsSecureEAP-TLS, certificate from your MDM over SCEPA student VLAN with its own policyEnds with the student's directory account
Short-term staff: substitute teachers and visiting specialistsxPSKIndividual key, MAC-bound (dated to the booking, no MDM)A staff-access VLAN with its own limitEnds on the last booked day
Classroom displays, printers and tablet cartsxPSKIndividual key, MAC-boundA device VLAN per class of deviceOne key per device, revoked when swapped
Cleaners, caterers and maintenance contractorsxPSKIndividual key, MAC-bound (time-limited, nothing to install)A contractor VLAN, a limit per keyEnds on the contract's end date
Heating controls, CCTV, door entry and bellsxPSKIndividual key, MAC-boundA building-systems VLAN, unreachable from studentsRotated or revoked per device by the site team

Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.

Schools: open, secure and xPSK

Three networks, each doing its own job

Identity decides the VLAN inside each network, so one SSID carries many groups.

Visitors and personal devices

Parents and event visitors use the captive portal. Staff and older students with their own devices join once through the Purple app.

  • Open evenings and parent events on the portal. SSO, social or SMS sign-in, consent recorded for GDPR and CCPA, under 15 minutes to add to a controller.
  • Personal devices with no MDM. One sign-in in the Purple app with the school's Google, Microsoft or Okta account installs a pass on Windows, macOS, Linux, iOS and Android.
  • Guests apart from students. The guest VLAN has client isolation on and no route to the student or staff VLANs.
Illustration

Lifecycle

Key lifecycle: book, place, operate, close

The same four moves serve a substitute teacher and a wall display, tied to the staff booking, the directory and the site's asset list.

Issue from the booking or the asset list

A substitute teacher's key is created with the booking's dates. Displays and printers are keyed when fitted, from the console, a bulk list or the Purple API, each bound to its MAC.

Illustration

Place on a VLAN by group and device class

RADIUS returns the VLAN, role or group policy, depending on your vendor. Your access points and gateway enforce it, and inter-VLAN rules live on your gateway.

Illustration

Operate from one log across every site

Every accept and reject carries its reason, by member of staff, student and device, streamed to Sentinel, Splunk, Elastic or Datadog.

Illustration

Close on the date, or when the directory says

A booking key stops on its last day. A leaver is disabled once in the directory, and RADIUS CoA ends the live session on access points that support it.

Illustration

One authentication log

One authentication log across every site

Staff certificates, booking keys and device keys land in one log, so "who is on the network today, and should they be" is a query.

  • Which substitute teacher keys are live today, and which expired on schedule.
  • Which classroom devices are on the network at each site, and on which VLAN.
  • Which accounts were rejected, by which method, and why.
  • Which contractor keys are still live after the contract ended.
Illustration

Audit

Filtering duties: what the VLAN map and the log evidence

Duties differ by country. A VLAN per group puts each policy where it applies, and the log shows which device was on which VLAN. Evidence, not a claim of compliance.

  • CIPA

    Schools and libraries that take E-rate discounts must filter internet access for minors. One VLAN for student devices lets one policy cover them, apart from staff and guests.

Works with

Your directory, your MDM, your SIEM, your access points

Nothing is replaced. Purple Access sits on the systems your team already runs.

  • Identity providers

    Over SAML and SCIM. Group membership decides the VLAN.
    • Google Workspace
    • Microsoft Entra ID
    • Okta
  • Device management

    EAP-TLS certificates delivered over SCEP, with a compliance-gated join.
    • Microsoft Intune
    • Jamf Pro
    • JumpCloud
    • Kandji
    • Hexnode
    • Iru
    • Addigy
  • SIEM

    The authentication log, over webhook or syslog.
    • Microsoft Sentinel
    • Splunk
    • Elastic
    • Datadog
  • Access points

    Mixed estates are supported.
    • Cisco Meraki
    • HPE Aruba
    • Ruckus
    • Juniper Mist
    • Ubiquiti UniFi
    • Cambium
    • Extreme
    • Fortinet

Proof

A platform you can put in front of a governor

ISO 27001 and Cyber Essentials Plus are held by Purple, and the RADIUS SLA is in your contract.

80,000+
venues run on Purple, in 90 countries
500M
logins a year
ISO 27001
and Cyber Essentials Plus, held by Purple
99.9%
cloud RADIUS uptime SLA, in your contract

Add-on: Purple Shield

Add protective DNS with Purple Shield

Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.

Illustration

FAQ

Questions IT leads ask

How does a substitute teacher get on without a directory account?

A key with a start and an end date, issued from the console or the Purple API. It needs no account, no MDM and nothing installed, and it stops on the last booked day.

How does a classroom display with no browser and no supplicant get on?

To the display, its xPSK key is an ordinary WPA2-Personal passphrase. MAC binding ties the key to that display, so it cannot become a second shared password, and swapping the display is one revocation.

Do we need new access points?

No. Purple Access is a cloud overlay on the access points your schools and sites already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.

Can a group of schools run every site from one place?

Yes. One cloud RADIUS and one authentication log cover every site, with your directory deciding the VLAN, on a mixed estate of access point brands.

How does content filtering apply to students, staff and guests?

Each group lands on its own VLAN, and Purple Shield sets a DNS policy per VLAN and by time of day. Shield bolts onto Access or runs standalone, and the filtering follows the VLAN, not the access point.

Is xPSK the same as iPSK, PPSK, DPSK, MPSK or EasyPSK?

Yes. xPSK is our name for the capability each vendor ships under its own: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK. Purple runs all of them from one platform, on a mixed estate.

Book a demo: we issue and revoke a key on a live network

Bring one school's worth of devices: a substitute teacher's phone, a wall display, a printer and a staff laptop. We issue each a key or a certificate, place it on its VLAN and revoke one live, on the access points you already run.

  1. Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
  2. We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
  3. You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.

Your design session

Your live key demo

A Purple network engineer runs the demo with you, on your kind of estate.