Skip to content
xPSK use case

Many organizations, one building: every tenant sealed on its own VLAN, with a personal WiFi key per device

Each tenant wants its own network, and building one per tenant is slow and costly. One set of access points returns a VLAN or role per organization, keys and certificates ride on it, and the landlord keeps one dashboard and one log.

  • Vancouver International Airport
  • Kinetic Melbourne Airport
  • 80,000+ venues in 90 countries
Illustration
Book my design session

The problem

A network per tenant does not scale: radios, uplinks and SSIDs all multiply

Tenants want their own network, assessors want proof of separation and the landlord wants one set of radios. Building a network per tenant answers the first and breaks the other two.

  • An SSID per tenant: 8 to 10 SSIDs use 15 to 25% of channel airtime, before a single client sends data.
  • One shared password across tenants, so a leaver at one company still knows the key to every other company's printers.
  • Every joiner, leaver and new device is a ticket to the landlord's IT team.
  • Evidence that one tenant cannot reach another's network is a slide in a deck, not a log.

How it works

Issue, bind and place, operate, revoke

One organization is the unit. Everything beneath it, people and devices, inherits its VLAN or role.

One organization, one key set

Create the organization once. Its staff sign in on the tenant's own Entra ID, Okta or Google Workspace, and its devices get keys from the console, in bulk from a list, or through the Purple API.

Illustration

Bind to a device, place on the tenant's VLAN

Each key is bound to the device's MAC address, and RADIUS returns the organization's VLAN or role with its own bandwidth limit. Your access points enforce it, and a shared-service rule, such as a common printer, lives on your gateway.

Illustration

One log across every organization

Every accept and reject carries the organization, the method and the reason, so the landlord answers which tenant, which device and why from one place, and streams it to the SIEM.

Illustration

Revoke one device, one person or one tenant

Withdraw a key and only that device drops, with RADIUS CoA ending its live session on access points that support it. A tenant that leaves has its keys revoked and nobody else is touched.

Illustration

Open, secure or xPSK

Which of the three networks, for which party in the building

Which of the three networks, for which party in the building
Who or what connectsNetworkAuthenticationPlacementWhat starts and ends access
Visitors at reception, shoppers and the publicOpenCaptive portal sign-in, consent recordedA guest VLAN with client isolation onSession and consent recorded at sign-in
Landlord and building management staffSecureEAP-TLS, certificate from your MDM over SCEPA landlord VLAN, by directory groupAccount disabled in the directory ends access
A tenant's laptops and phonesSecureEAP-TLS, certificate from your MDM over SCEP (the tenant's own MDM and directory)The tenant's own VLAN or roleEnds when the tenant disables the account, or the tenancy ends
A tenant's printers, screens and registersxPSKIndividual key, MAC-boundThe tenant's VLAN, apart from every other tenantOne key per device, revoked alone
Fit-out and maintenance contractorsxPSKIndividual key, MAC-bound (time-limited, no MDM)One unit's VLAN onlyEnds on the date set, with nothing to uninstall
Elevators, HVAC and access controlxPSKIndividual key, MAC-boundA building-systems VLAN, apart from every tenantOne key per controller, revoked with the device

Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.

What it covers

What you can do with it

  • A VLAN or role per organization

    RADIUS returns it at authentication, so the SSID never has to change when a tenant arrives.
  • Keys in bulk, ended on a date

    A list of units, stands or staff becomes keys in one import, each with an end date.
  • One SSID for every tenant

    Tenant 51 adds keys, not beacons, so airtime is the same at 5 tenants and at 500.

Where it matters

The industries that run into this most

Proof

Concessions on their own keys, at airport scale

Vancouver International Airport and Kinetic Melbourne Airport put their concessions on their own keys.

Vancouver
International Airport runs on Purple, concessions on their own keys
Melbourne
Kinetic Melbourne Airport runs on Purple, concessions on their own keys
80,000+
venues run on Purple, in 90 countries

FAQ

Questions IT leads ask

How many tenants fit on one SSID?

One xPSK SSID carries every tenant, each on its own VLAN or role. There is no per-SSID key ceiling, so a new tenant adds keys and not beacons.

Do we need new access points?

No. Purple Access is a cloud overlay on the access points your buildings already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.

Who issues and revokes the keys?

The landlord's IT team, from the console or the Purple API, with a branded self-service portal for contractors. Each key is unique to one device and bound to it by MAC address.

Is a VLAN per tenant enough to keep tenants apart?

The VLAN separates tenants at layer 2, and your gateway or firewall decides what, if anything, may cross between them, such as a shared printer. Purple decides which VLAN each connection lands in and logs why.

What if parts of the building run different access point brands?

Purple runs each vendor's per-device key capability on a mixed estate: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK.

Does xPSK take our WiFi out of PCI scope?

Purple never touches payment card data. Each register and card machine sits on its own key and its own VLAN, apart from guests and staff, and every authentication is logged as evidence for PCI DSS Req 8 and 10. We hand your QSA the VLAN map and the authentication log to test against.

Book a demo: we issue and revoke a key on a live network

Bring the list of tenants and what each runs. We create two organizations, issue a key in each and revoke one live, on the access points you already own.

  1. Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
  2. We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
  3. You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.

Your design session

Your live key demo

A Purple network engineer runs the demo with you, on your kind of estate.