Serviced apartments: guests on the portal, staff on EAP-TLS, a personal WiFi key per client and device
Guests who stay for weeks join on the portal, or on a key whose end date you set. Corporate clients' staff land on one company network across every apartment they hold. Smart locks and thermostats stay on their own keys through every changeover.
- 80,000+ venues in 90 countries
- 500 million logins a year
- 99.9% RADIUS uptime SLA
- 99.999% uptime
Who is on the serviced apartments and long stay network
Who is on the property network, and where each one lands
Unit devices keep their keys through every changeover, each guest's access ends on its own date, and a corporate client's staff share one company network across apartments.
| Who or what connects | Network | Authentication | Placement | What starts and ends access |
|---|---|---|---|---|
| Short-stay guests | Open | Captive portal sign-in, consent recorded (or SSO, social, SMS) | Guest VLAN, client isolation on | Consent recorded at sign-in |
| Returning guests | Secure | Passpoint or OpenRoaming profile | Guest VLAN, with no portal on return | Profile installed once, valid at every property that runs it |
| Housekeeping, reception and operations staff | Secure | EAP-TLS, certificate from your MDM over SCEP | VLAN by directory group | Account disabled, and RADIUS CoA ends the session |
| Long-stay guests | xPSK | Individual key, MAC-bound (an end date set at issue) | A guest-class VLAN, with a bandwidth limit per key | Ends on the date set, or revoked alone |
| A corporate client's staff, across several apartments | xPSK | Individual key, MAC-bound (grouped under one company) | One role and VLAN per corporate client | Ends with the client's contract, one client at a time |
| Smart locks, thermostats and leak sensors | xPSK | Individual key, MAC-bound | A device VLAN per class, unreachable from guests | The key outlives every guest and ends when the device is replaced |
| Maintenance and refurbishment contractors | xPSK | Individual key, MAC-bound (time-limited, no MDM) | A VLAN and bandwidth limit per key | Ends on the day the job does |
Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.
Serviced apartments and long stay: open, secure and xPSK
Three networks, each doing its own job
Identity decides the VLAN inside each network, so one SSID carries many groups.
Guests and cleaners' phones: portal and onboarding lane
The guest lane for the first night and the BYOD lane for staff who bring their own phone.
- Sign-in methods per brand. SSO, Google, Apple, Facebook or SMS, and under 15 minutes to add the splash URL and RADIUS to a controller.
- Cleaners and agency staff with no MDM. Sign in once in the Purple app and a WiFi pass installs on Windows, macOS, Linux, iOS and Android.
Operations staff and returning guests: EAP-TLS and Passpoint
One WPA-Enterprise SSID for managed devices. Cloud RADIUS checks the directory and returns the VLAN for the group.
- EAP-TLS from your MDM. Microsoft Intune, Jamf Pro, JumpCloud, Kandji, Hexnode, Iru and Addigy deliver the certificate over SCEP. Setup is five to ten minutes, once.
- Directory groups decide the VLAN. Entra ID, Okta or Google Workspace over SAML and SCIM. Disable a leaver once and every building stops authenticating them.
- Passpoint for guests who return. A profile installed once joins every property that runs it, with free OpenRoaming through the Connect license.
Stays, clients and unit devices: a key each, on one SSID
Everything that has no 802.1X supplicant, no screen or no certificate store, and every guest who should not touch a portal for a month, gets a key on one SSID, MAC-bound where the device has a fixed MAC.
- Locks and thermostats survive changeover. Each unit device keeps its key and device VLAN between guests, so a departure revokes the guest's key and never touches the lock.
- One company network per corporate client. A client's staff keys share one role and VLAN across several apartments, with the client's own end date, and no other client sees it.
- Keys with an end date for long stays. A guest who stays for weeks joins once with a key, with no weekly portal sign-in, and the key stops on the date you set when it was issued.
- Contractors with nothing to install. A time-limited key from the self-service portal or the Purple API, ending on the day the job does.
- A private network per apartment for the booking. Each apartment gets a private network of its own for the length of the booking.
Lifecycle
Key lifecycle: commission, place, operate, change over
Two lifetimes share one SSID: the unit's devices live as long as the hardware, a guest's key as long as the booking.
Issue to the unit and to the stay
Key each lock and thermostat at commissioning, and each long-stay guest or client's staff on arrival, from the console, in bulk or through the Purple API, with an end date from the booking.
Place by class: guest, client, device
RADIUS returns a VLAN, role or group policy, depending on your vendor. Guests and unit devices land on separate VLANs, each corporate client gets one of its own, and inter-VLAN rules live on your gateway.
Operate one log across the portfolio
Every accept and reject carries the building, the method and the reason, across every property, streamed to Microsoft Sentinel, Splunk, Elastic or Datadog.
Change over one guest, one client or one device
A departure ends one key and the lock keeps its own. A client's contract ending revokes that client's keys alone, with RADIUS CoA ending live sessions on access points that support it.
One authentication log
One authentication log across every building you operate
Guest, client, staff and device authentications share a log, so "is this lock online and on the right VLAN" is a query and not a site visit.
- Which unit devices are online at each building, and on which VLAN.
- Which long-stay keys are still live after their end date.
- Which corporate client's staff authenticated today, and in which apartments.
Works with
Your directory, your MDM, your SIEM, your access points
Nothing is replaced. Purple Access sits on the systems your team already runs.
Identity providers
Over SAML and SCIM. Group membership decides the VLAN.- Microsoft Entra ID
- Okta
- Google Workspace
Device management
EAP-TLS certificates delivered over SCEP, with a compliance-gated join.- Microsoft Intune
- Jamf Pro
- JumpCloud
- Kandji
- Hexnode
- Iru
- Addigy
SIEM
The authentication log, over webhook or syslog.- Microsoft Sentinel
- Splunk
- Elastic
- Datadog
Access points
Mixed estates are supported.- Cisco Meraki
- HPE Aruba
- Ruckus
- Juniper Mist
- Ubiquiti UniFi
- Cambium
- Extreme
- Fortinet
Identity providers: setup and mappingDevice management: setup and mappingSIEM: setup and mappingHardware setup by vendor
Proof
Run across a portfolio of buildings
- 80,000+
- venues run on Purple, in 90 countries
- 500M
- logins a year
- ~2M
- people onboarded every day
- 99.9%
- cloud RADIUS uptime SLA, in your contract
Add-on: Purple Shield
Add protective DNS with Purple Shield
Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.
FAQ
Questions IT leads ask
Do we need new access points in each apartment building or aparthotel?
No. Purple Access is a cloud overlay on the access points your buildings already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.
Can a guest who stays for a month avoid the portal every week?
Yes. A Passpoint profile rejoins automatically on every return, and a key issued with an end date joins like an ordinary WPA2-Personal network until that date.
How does one corporate client's staff share a network across apartments?
The client is one role and VLAN, and every key issued to its staff returns it in any apartment. Revoking one person's key leaves the rest connected.
What happens to a lock or thermostat's key at changeover?
Nothing. The device keeps its key and VLAN, because its lifetime is the hardware's and not the guest's. Each key is bound to the device by MAC and held on the access point side under each vendor's name for it (Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK).
Is xPSK one SSID or one per household, tenant or device?
One SSID. Every key on it has its own VLAN, policy and bandwidth limit, returned by RADIUS at authentication, and there is no per-SSID key ceiling. Adding a key never adds a beacon.
Book a demo: we issue and revoke a key on a live network
Bring one apartment's worth of devices: a lock, a thermostat, a guest's laptop and a client's staff phone. We issue each a key, place it on its VLAN and revoke one live, on the access points you already run.
- Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
- We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
- You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.
Your design session
Your live key demo
A Purple network engineer runs the demo with you, on your kind of estate.