Collapse your network to three SSIDs
Every extra SSID costs you airtime, risk and tickets right now. Open for guests and onboarding, secure for everyone you trust, xPSK for everything else, and identity deciding the VLAN. Three is the design. Skip per-device keys and it is two. In education, eduroam makes it four.
- 8 to 10 SSIDs use 15 to 25% of channel airtime
- Typical vendor guidance is three to five SSIDs
Planner
Plan your three SSIDs
Tick what connects to your network today and see where each group lands. Nothing you tick leaves this page.
Your plan: 3 SSIDs.
- Guests and visitorsCaptive portal, consent recorded
- Staff on managed devicesEAP-TLS from your MDM
- Tills, screens, CCTV and sensorsA key per device
Book a design session with this planThe full planner, on purple.ai
The airtime maths
Beacons are not free
Every SSID beacons
Each SSID advertises itself at the lowest basic rate, whether anyone is using it or not.
8 to 10 SSIDs, 15 to 25% of airtime
That overhead is airtime your guests, staff and devices never get back.
Three SSIDs and a 12 Mbps basic rate win it back
Fewer beacons, sent faster. Typical vendor guidance is three to five SSIDs.
The split
How three SSIDs split your estate
Open takes guests and onboarding, secure takes everyone you trust, and xPSK takes everything that cannot hold a certificate. Inside each, RADIUS attributes put every user and device on the right VLAN by identity, and the model flexes from two to four SSIDs to suit your policy. Three is the design. Skip per-device keys and it is two. In education, eduroam makes it four.
Open: guests in, and BYOD on its way to a certificate
Guest WiFi through a captive portal, and the onboarding lane for BYOD and unmanaged devices before they get a certificate.
- SSO, Google, Apple, Facebook and SMS sign-in
- Hotel PMS room check
- Visitors connected before they arrive
- Consent recorded for GDPR and CCPA
Secure: one passwordless SSID for everyone you trust
One WPA-Enterprise SSID for every trusted user, passwordless and certificate-based. Staff on EAP-TLS with your MDM and a compliance-gated join, and secure guest access with Passpoint and free OpenRoaming.
- EAP-TLS certificates delivered by your MDM
- Conditional Access and device posture checked at every join
- Entra ID, Okta and Google Workspace decide the VLAN
- Passpoint profile installs once, connects every visit
xPSK, the Swiss Army knife
One SSID, a key per device, person or tenant. Each key gets its own VLAN, policy and bandwidth limit, and you revoke one without touching the rest. Works on Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK.
- Things: tills, screens, CCTV, sensors
- Communities: a private network per resident
- Concessions: each mall or airport tenant on its own key
The risk case
Shared keys are an audit finding waiting to happen
PCI DSS v4.0.1 Req 2.3.2 says wireless keys must change when anyone who knows them leaves. The UK Cyber Security Breaches Survey 2025 found 43% of businesses breached or attacked, 67% of medium and 74% of large.
- Certificates for everyone you trust: nothing to share.
- A key per device for everything else: rotate one, not all.
- Every accept and reject logged, by person and device.
Comparison
Seven SSIDs and a shared password, or three SSIDs on Purple
The same estate, run two ways. Read across and decide which one you want to defend in your next audit.
| Three SSIDs on Purple | Shared passwords, seven SSIDs | |
|---|---|---|
| Isolation | Three SSIDs on PurpleIdentity decides the VLAN. Each resident, tenant or device group sits in its own segment. | Shared passwords, seven SSIDsEveryone on an SSID shares one segment, so one compromised device can see the rest. |
| Revoking | Three SSIDs on PurpleDisable one account or one key. Nobody else notices. | Shared passwords, seven SSIDsChange the password, then re-key every device that knew it. |
| Headless devices | Three SSIDs on PurpleEach till, screen or camera gets its own key, VLAN and bandwidth limit. | Shared passwords, seven SSIDsDevices share the guest or staff password, or get another SSID. |
| Lifecycle | Three SSIDs on PurpleJoiners and leavers flow from Entra ID, Okta or Google Workspace. Certificates auto-renew. | Shared passwords, seven SSIDsLeavers keep the password until someone remembers to rotate it. |
| Casting | Three SSIDs on PurplemDNS reflection keeps AirPlay and Chromecast inside each resident's private network. | Shared passwords, seven SSIDsEvery TV in the building shows up in every resident's cast list. |
| Audit | Three SSIDs on PurpleEvery accept and reject logged with its reason, by person and device, and streamed to your SIEM. | Shared passwords, seven SSIDsA log of a shared credential tells you nothing about who connected. |
FAQ
Common questions
We have more SSIDs and they work. Why change?
They work, and they are costing you. Every SSID beacons at the lowest basic rate, and 8 to 10 SSIDs spend 15 to 25% of airtime on overhead. Three SSIDs plus a 12 Mbps basic rate win it back.
I only have two networks. Do I need three?
Then where are the CCTV and the tills? If they share the guest or staff password, that is your audit finding. The model flexes from two to four SSIDs to suit your policy. Three is the design. Skip per-device keys and it is two. In education, eduroam makes it four.
Do we have to rip and replace our access points?
No. Purple Access is a cloud overlay on Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet, and mixed estates are supported. Keep the hardware. Lose the shared passwords.
Isn't PSK insecure?
A shared PSK is. A unique key per device, bound to an identity and a VLAN and revocable on its own, is not. Certificates stay the default, and xPSK is for everything that cannot hold one.
Turn your planner result into a design
Bring your planner result. A Purple engineer maps it onto your access points, and you keep the plan. All in a 45-minute design session.
- Get your three-SSID plan in 45 minutesTell us what runs on your WiFi today, and a Purple network engineer maps it with you.
- Map your SSIDs onto threeOpen, secure and xPSK, on the access points you already own. You leave with the plan.
- Prove it on one site firstJudge the result on tickets and audit evidence, then roll out.
Your design session
45 minutes. Your estate. A plan you keep.
Led by a Purple network engineer. No slides. You keep the plan.