Skip to content
Three SSIDs

Collapse your network to three SSIDs

Every extra SSID costs you airtime, risk and tickets right now. Open for guests and onboarding, secure for everyone you trust, xPSK for everything else, and identity deciding the VLAN. Three is the design. Skip per-device keys and it is two. In education, eduroam makes it four.

  • 8 to 10 SSIDs use 15 to 25% of channel airtime
  • Typical vendor guidance is three to five SSIDs
Book my design session

Planner

Plan your three SSIDs

Tick what connects to your network today and see where each group lands. Nothing you tick leaves this page.

How many SSIDs do you broadcast today?
What connects to your network?

Your plan: 3 SSIDs.

Network 1Open
  • Guests and visitorsCaptive portal, consent recorded
Network 2Secure
  • Staff on managed devicesEAP-TLS from your MDM
Network 3xPSK
  • Tills, screens, CCTV and sensorsA key per device

Book a design session with this planThe full planner, on purple.ai

The airtime maths

Beacons are not free

Every SSID beacons

Each SSID advertises itself at the lowest basic rate, whether anyone is using it or not.

8 to 10 SSIDs, 15 to 25% of airtime

That overhead is airtime your guests, staff and devices never get back.

Three SSIDs and a 12 Mbps basic rate win it back

Fewer beacons, sent faster. Typical vendor guidance is three to five SSIDs.

The split

How three SSIDs split your estate

Open takes guests and onboarding, secure takes everyone you trust, and xPSK takes everything that cannot hold a certificate. Inside each, RADIUS attributes put every user and device on the right VLAN by identity, and the model flexes from two to four SSIDs to suit your policy. Three is the design. Skip per-device keys and it is two. In education, eduroam makes it four.

Open: guests in, and BYOD on its way to a certificate

Guest WiFi through a captive portal, and the onboarding lane for BYOD and unmanaged devices before they get a certificate.

  • SSO, Google, Apple, Facebook and SMS sign-in
  • Hotel PMS room check
  • Visitors connected before they arrive
  • Consent recorded for GDPR and CCPA
Illustration

The risk case

Shared keys are an audit finding waiting to happen

PCI DSS v4.0.1 Req 2.3.2 says wireless keys must change when anyone who knows them leaves. The UK Cyber Security Breaches Survey 2025 found 43% of businesses breached or attacked, 67% of medium and 74% of large.

  • Certificates for everyone you trust: nothing to share.
  • A key per device for everything else: rotate one, not all.
  • Every accept and reject logged, by person and device.
Illustration

Comparison

Seven SSIDs and a shared password, or three SSIDs on Purple

The same estate, run two ways. Read across and decide which one you want to defend in your next audit.

Shared passwords and seven SSIDs compared with three SSIDs on Purple Access
Three SSIDs on PurpleShared passwords, seven SSIDs
IsolationThree SSIDs on PurpleIdentity decides the VLAN. Each resident, tenant or device group sits in its own segment.Shared passwords, seven SSIDsEveryone on an SSID shares one segment, so one compromised device can see the rest.
RevokingThree SSIDs on PurpleDisable one account or one key. Nobody else notices.Shared passwords, seven SSIDsChange the password, then re-key every device that knew it.
Headless devicesThree SSIDs on PurpleEach till, screen or camera gets its own key, VLAN and bandwidth limit.Shared passwords, seven SSIDsDevices share the guest or staff password, or get another SSID.
LifecycleThree SSIDs on PurpleJoiners and leavers flow from Entra ID, Okta or Google Workspace. Certificates auto-renew.Shared passwords, seven SSIDsLeavers keep the password until someone remembers to rotate it.
CastingThree SSIDs on PurplemDNS reflection keeps AirPlay and Chromecast inside each resident's private network.Shared passwords, seven SSIDsEvery TV in the building shows up in every resident's cast list.
AuditThree SSIDs on PurpleEvery accept and reject logged with its reason, by person and device, and streamed to your SIEM.Shared passwords, seven SSIDsA log of a shared credential tells you nothing about who connected.

FAQ

Common questions

We have more SSIDs and they work. Why change?

They work, and they are costing you. Every SSID beacons at the lowest basic rate, and 8 to 10 SSIDs spend 15 to 25% of airtime on overhead. Three SSIDs plus a 12 Mbps basic rate win it back.

I only have two networks. Do I need three?

Then where are the CCTV and the tills? If they share the guest or staff password, that is your audit finding. The model flexes from two to four SSIDs to suit your policy. Three is the design. Skip per-device keys and it is two. In education, eduroam makes it four.

Do we have to rip and replace our access points?

No. Purple Access is a cloud overlay on Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet, and mixed estates are supported. Keep the hardware. Lose the shared passwords.

Isn't PSK insecure?

A shared PSK is. A unique key per device, bound to an identity and a VLAN and revocable on its own, is not. Certificates stay the default, and xPSK is for everything that cannot hold one.

Turn your planner result into a design

Bring your planner result. A Purple engineer maps it onto your access points, and you keep the plan. All in a 45-minute design session.

  1. Get your three-SSID plan in 45 minutesTell us what runs on your WiFi today, and a Purple network engineer maps it with you.
  2. Map your SSIDs onto threeOpen, secure and xPSK, on the access points you already own. You leave with the plan.
  3. Prove it on one site firstJudge the result on tickets and audit evidence, then roll out.

Your design session

45 minutes. Your estate. A plan you keep.

Led by a Purple network engineer. No slides. You keep the plan.