Skip to content
xPSK use case

Move-in and move-out: revoke one personal WiFi key, never the shared password

A shared passphrase has to change when anyone who knows it leaves, and changing it disconnects everybody else. With a personal WiFi key per household on one xPSK SSID (iPSK, PPSK, DPSK, MPSK), a move-out is one revocation and every other resident, lock and thermostat stays online.

  • 60% fewer helpdesk tickets at move-in
  • ~1 million residents on Purple
  • University of New Brunswick on iPSK
Illustration
Book my design session

The problem

A shared password turns every move-out into a network-wide event

One passphrase is held by every device on the SSID. It is a credential that cannot be taken back from one person without taking it from all of them.

  • Changing the passphrase drops every device on the SSID at once, and each change is a mass reconnect of TVs, speakers, thermostats and locks.
  • Not changing it leaves the previous occupant with a working key. The principle is written down in PCI DSS v4.0.1 Req 2.3.2 says wireless keys must change when anyone who knows them leaves.
  • A device-by-device fix is a ticket per household, so a turnover peak such as September in student housing becomes a helpdesk queue.
  • Locks, thermostats and leak sensors belong to the unit and not to the person, so they cannot follow the resident's phone to a new key.
Illustration

How it works

Issue at move-in, revoke at move-out, touch nobody else

The household is the unit. Its keys are created from the lease or booking record and ended from the same place.

Create the household's keys from the record

A move-in creates the keys from the console, a bulk import or the Purple API, so they exist before arrival. Residents collect theirs in the Purple app with a Microsoft, Google or Okta account, or from a branded self-service portal.

Illustration

Bind each key to a device and place it

MAC binding ties a key to its device, and RADIUS returns the household's VLAN or role with its own bandwidth limit. The unit's locks, thermostats and leak sensors carry device keys of their own, so they are not part of the tenancy.

Illustration

Answer "why is this offline" from one log

Every accept and reject is logged with the key, the device, the VLAN and the reason, and streams to Microsoft Sentinel, Splunk, Elastic or Datadog. A move-in ticket is a search, not a site visit.

Illustration

Revoke the household, end the live session

Withdraw the household's keys and RADIUS CoA ends their live sessions on access points that support it. Other households carry on, the unit's device keys stay online, and the next lease gets new keys on the same SSID.

Illustration

Open, secure or xPSK

Which of the three networks, for which party at move-in and move-out

Which of the three networks, for which party at move-in and move-out
Who or what connectsNetworkAuthenticationPlacementWhat starts and ends access
Prospects at viewings and visitors in receptionOpenCaptive portal sign-in, consent recordedA guest VLAN with client isolation onSession and consent recorded at sign-in
On-site team, concierge and maintenance staffSecureEAP-TLS, certificate from your MDM over SCEP (managed devices, groups from Entra ID, Okta or Google Workspace)VLAN by directory groupAccount disabled in the directory ends access
Residents and their householdsxPSKIndividual key, MAC-boundA VLAN or role per household, with its own bandwidth limitIssued at move-in and revoked at move-out, with nothing else changing
Locks, thermostats and leak sensors in the apartmentxPSKIndividual key, MAC-boundA device VLAN per class, apart from residentsStay online between tenancies, revoked alone when replaced
Cleaners and turnover contractorsxPSKIndividual key, MAC-bound (time-limited, no MDM)One unit's or one block's VLAN onlyEnds on the date set, with nothing to uninstall

Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.

What it covers

What you can do with it

  • Keys before arrival

    Import the move-in list and the keys exist before the first box is unpacked. US university housing across 40 buildings saw 60% fewer helpdesk tickets at move-in.
  • Room and unit swaps

    A resident who changes apartment or room keeps their keys, because placement follows the person. The unit's device keys stay with the unit.
  • Keys timed to the stay

    A summer let, a one-week stay or a twelve-month lease gets its end date at issue, so expiry is built in and not a chore.
  • Devices that outlive tenancies

    Thermostats, locks and leak sensors stay online between lease changes, so the next resident arrives to a building that already works.

Where it matters

The industries that run into this most

Proof

Turnover at university scale

US university housing across 40 buildings saw 60% fewer helpdesk tickets at move-in, and about 1 million students and residents run on Purple community networks.

60%
fewer helpdesk tickets at move-in, US university housing across 40 buildings
~1M
students and residents on Purple community networks
iPSK
University of New Brunswick runs iPSK on Purple

Add-on: Purple Shield

Add protective DNS with Purple Shield

Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.

Illustration

FAQ

Questions IT leads ask

Why not rotate the shared password at each move-out?

One passphrase is held by every device on the SSID. Rotating it disconnects every household at once, and not rotating it leaves the leaver with a working key. A key per household turns a move-out into one revocation.

Is xPSK one SSID or one per household, tenant or device?

One SSID. Every key on it has its own VLAN, policy and bandwidth limit, returned by RADIUS at authentication, and there is no per-SSID key ceiling. Adding a key never adds a beacon.

What stops a key being passed to a neighbor?

MAC binding ties each key to its device, so a key cannot become a second shared password. It is strongest on fixed-address devices such as locks, TVs and sensors. A household that needs another device gets another key.

What does revoking one key do to everyone else?

Nothing. Each key is its own entry in RADIUS, bound to its device by MAC, so withdrawing one ends that device's access and leaves every other key connected. A live session is ended with RADIUS CoA on access points that support it.

Where do staff and visitors fit?

On the other two networks. Staff sign in on the secure network with EAP-TLS or directory groups, prospects and visitors on the open network through the portal, and each lands on its own VLAN. xPSK carries the households and the devices that cannot hold a certificate.

Do we need new access points?

No. Purple Access is a cloud overlay on the access points your buildings already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.

Is xPSK the same as iPSK, PPSK, DPSK, MPSK or EasyPSK?

Yes. xPSK is our name for the capability each vendor ships under its own: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK. Purple runs all of them from one platform, on a mixed estate.

Book a demo: we issue and revoke a key on a live network

Bring a move-out list and the devices that live in a unit. We issue a household's keys and revoke one live, while the rest of the network stays connected.

  1. Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
  2. We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
  3. You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.

Your design session

Your live key demo

A Purple network engineer runs the demo with you, on your kind of estate.