Skip to main content

Passpoint WiFi

By Devi Jina
29 November 2023
4 min read
Passpoint WiFi
Interactive technical tool

Passpoint WiFi architecture and readiness calculator

Calculate recovered guest connections, cellular offload bandwidth, and enterprise hardware compatibility when upgrading from captive portals or shared passphrases to Hotspot 2.0.

Select venue environment
2k150k300k+
Current baseline: Medium risk (captive portal)
10% (minimal)50% (typical)85% (severe)
Meraki-MR 28.1+ / IOS-XE 17.6+
Recovered Connected Users
+14,280
+121% connection rate lift
Eliminates splash screen abandonment by automatically provisioning profiles via Hotspot 2.0.
Cellular Offload Volume
10.4 TB
10,680 GB monthly
Carrier offloading unburdens local 5G spectrum and enables venue data monetisation.
Enterprise Security Tier
WPA3-Enterprise
802.1X per-client encryption
Protects every session with dynamic AES keys, eliminating open WiFi eavesdropping and evil twin attacks.
Return-Visit Identity Retention
100%
Immune to MAC rotation
Passpoint profiles authenticate cryptographic certificates, restoring repeat-visitor analytics blinded by iOS and Android privacy features.

Access point deployment specification: Cisco Catalyst & Meraki

OI: 5A-03-BA-00-00 (OpenRoaming consortium)
Minimum firmware versionMeraki-MR 28.1+ / IOS-XE 17.6+
ANQP protocol supportNative Hotspot 2.0 profile in dashboard & WLC
Federation compatibilityOpenRoaming & eduroam ready

Full ANQP element exchange supported. Meraki dashboard allows 1-click Passpoint SSID provisioning with automatic Cloud RADIUS alignment.

Ready to deploy Passpoint across your enterprise estate?
Purple provides zero-touch Passpoint profile push, Cloud RADIUS, and OpenRoaming federation for enterprise venues.
Explore Passpoint features →
Interactive Architecture Tool

Hotspot 2.0 & Passpoint Venue Readiness Estimator

Configure your venue parameters to evaluate Passpoint auto-connect rates, cellular offload potential, and enterprise WiFi security benefits.

1. Venue Category
2. WiFi AP Hardware
3. Monthly Visitor Footfall
Recommended Architecture

Hotel Guest & Loyalty Passpoint Architecture

Zero-Click Auto Connect
94% Automatic Re-Connection across properties
Security Standard
WPA2/WPA3-Enterprise (EAP-TTLS / Passpoint R2)
Cellular Offload Potential
High (80% guest cellular-to-WiFi offload)
Hardware Compatibility
Cisco Meraki / Catalyst WLC (Native Passpoint 2.0 ANQP Support)
Deployment Timeframe: Same Day Cloud ConfigurationPlatform: Purple Cloud RADIUS & Unified Passpoint Profile Manager

Passpoint WiFi (also known as Hotspot 2.0 or IEEE 802.11u) is an enterprise wireless standard designed to automate network discovery, authentication, and WPA2/WPA3-Enterprise encryption. Passpoint enables mobile devices to connect automatically to secure WiFi networks without captive portal splash screens, manual web forms, or recurring password prompts.

By eliminating friction from guest WiFi onboarding while encrypting over-the-air communications, Passpoint provides carrier-grade connectivity for enterprise venues, hospitality properties, retail chains, and transit hubs.

What is Passpoint WiFi and how does it work?

Traditional public guest WiFi networks require users to open browser splash pages, fill out form fields, or manually enter pre-shared keys. This creates user friction and leaves open networks vulnerable to unencrypted eavesdropping and evil twin attacks.

Passpoint solves these limitations by using Access Network Query Protocol (ANQP) during the initial 802.11 association. Before a device connects, ANQP allows the device and access point to exchange information regarding network identity, supported service providers, and authentication methods behind the scenes.

Key Takeaways

  • Zero-Click Auto-Connect: Devices automatically discover and authenticate on Passpoint-enabled networks without manual intervention.
  • WPA3-Enterprise Security: Every user session gets unique per-device encryption keys, preventing side-channel sniffing on public WiFi.
  • Cellular Offload Integration: Mobile carriers and venues offload data traffic from congested 5G/LTE spectrum directly onto high-speed WiFi networks.
  • Seamless Multi-Site Roaming: Users authenticate once and roam across thousands of participating locations automatically.

Passpoint WiFi vs traditional guest WiFi

Understanding how Passpoint compares to open guest networks and splash portals helps IT teams choose the optimal network architecture:

Feature Open Guest WiFi Captive Portal Passpoint WiFi (Hotspot 2.0)
User Onboarding Manual SSID selection Web splash page & form fill Automatic zero-click connect
Encryption None (Unencrypted open) None post-authentication WPA2/WPA3-Enterprise (802.1X)
Repeat Visits MAC re-authentication Frequent portal re-prompts Instant background re-connection
Cellular Offload Not supported Not supported Carrier-grade SIM & profile offload

Core benefits of Passpoint for enterprise venues

Implementing Passpoint delivers strategic advantages for venue operators, enterprise network architects, and IT departments:

1. Enhanced enterprise WiFi security

Unlike open public networks, Passpoint utilises EAP-TTLS or EAP-TLS protocols under WPA2/WPA3-Enterprise. This ensures every data packet transmitted over the air is encrypted, protecting users from man-in-the-middle attacks and packet sniffing.

2. Zero-friction guest experience

Visitors install a Passpoint profile once - via an app, QR code, or email link - and automatically connect whenever they enter any participating location. There are no web forms to complete or passwords to remember.

3. Cellular offloading and carrier partnerships

Major cellular providers use Passpoint to offload data traffic from congested mobile towers onto venue WiFi networks. Venues can partner with carriers to monetise network infrastructure while ensuring visitors maintain fast connectivity.

How Purple Cloud RADIUS simplifies Passpoint deployment

Deploying Passpoint traditionally required complex on-premise RADIUS infrastructure, custom digital certificate authorities, and manual client profile provisioning. Purple Cloud RADIUS streamlines this process into a centralized cloud platform.

Purple integrates directly with leading enterprise hardware providers - including Cisco Meraki, HPE Aruba, Ruckus Wireless, and Juniper Mist - allowing network administrators to push Passpoint configurations across thousands of access points instantly.

Deploy Passpoint WiFi across your enterprise network

See how Purple Cloud RADIUS and Passpoint provisioning automate secure guest connectivity and cellular offloading for your venue.

Explore Purple Guest WiFi

Frequently asked questions about Passpoint WiFi

Is Passpoint WiFi safe?

Yes. Passpoint uses enterprise-grade WPA2/WPA3-Enterprise security with 802.1X authentication. Unlike open public WiFi networks, Passpoint encrypts all traffic between the device and access point using unique session keys.

What is the difference between Passpoint and Hotspot 2.0?

Hotspot 2.0 is the technical specification developed by the WiFi Alliance and IEEE (802.11u standard). Passpoint is the official certification program managed by the WiFi Alliance to verify device and access point interoperability.

Do smartphones support Passpoint WiFi?

Yes. Modern operating systems - including iOS, Android, macOS, and Windows 10/11 - natively support Passpoint and Hotspot 2.0 profile installation and auto-connection.

How does Passpoint differ from OpenRoaming?

OpenRoaming is a global federation framework built on Passpoint technology. While Passpoint specifies the underlying authentication and encryption protocol, OpenRoaming provides the trust federation that connects identity providers (such as Google, Apple, or cellular carriers) with network providers worldwide.

Frequently asked questions

What is Passpoint WiFi and how does Hotspot 2.0 work?

Passpoint, also known as Hotspot 2.0, is a WiFi Alliance certified technology standard (based on IEEE 802.11u) that enables mobile devices to discover and automatically connect to secure WiFi networks without human intervention. Instead of searching for SSIDs and typing passphrases or completing web captive portals, a Passpoint-enabled smartphone or laptop queries the access point using Access Network Query Protocol (ANQP) in the background. If credentials match, it establishes an encrypted WPA2 or WPA3-Enterprise connection automatically.

How does Passpoint eliminate captive portal drop-off for guest WiFi?

Traditional captive portals require visitors to accept terms, submit forms, or verify email addresses on web splash screens - leading to 40% to 70% abandonment rates. Passpoint replaces this friction with zero-click background authentication. Once a visitor provisions a Passpoint profile on their device (via a native mobile app, a one-time onboarding link, or cellular carrier federation), their phone connects instantly every time they enter the venue, recovering up to 90% of otherwise lost guest network connections.

What is the difference between Passpoint WiFi and OpenRoaming?

Passpoint (Hotspot 2.0) is the underlying technical specification and client-access protocol certified by the WiFi Alliance. OpenRoaming is a global federation framework managed by the Wireless Broadband Alliance (WBA) built on top of Passpoint. While Passpoint defines how a device and access point communicate and authenticate, OpenRoaming establishes the legal, roaming, and RADIUS peering consortium (using Roaming Consortium Organisation Identifier 5A-03-BA-00-00) that allows credentials from identity providers like Google, Apple, Samsung, and cellular carriers to roam seamlessly across global venues.

How does Passpoint bypass private MAC address randomisation on iOS and Android?

Modern mobile operating systems rotate randomised private MAC addresses per SSID to protect user privacy, which breaks traditional captive portal recognition and repeat visitor analytics. Passpoint authenticates devices using cryptographic credentials (such as 802.1X certificates, SIM cards, or EAP-TLS keys) tied to an identity profile rather than hardware MAC addresses. This allows venue operators to accurately measure repeat visits and engagement while upholding user privacy and security.

Which enterprise access point hardware vendors support Passpoint?

Virtually all major enterprise wireless vendors natively support Passpoint Hotspot 2.0, including Cisco Catalyst and Meraki, HPE Aruba Networking, CommScope Ruckus, Juniper Mist, Ubiquiti UniFi (U6/U7 series), and Extreme Networks. Enabling Passpoint typically requires activating 802.11u parameters, configuring ANQP domain IDs and NAI realm lists, and connecting the access points to a Passpoint-compatible Cloud RADIUS server such as Purple.

How does Passpoint WiFi protect data compared to open networks?

Open public WiFi networks transmit unencrypted traffic that can be intercepted by eavesdroppers using packet sniffers or spoofed via evil twin rogue access points. Passpoint mandates WPA2-Enterprise or WPA3-Enterprise security with Protected Management Frames (PMF) and individual 802.1X encryption keys generated dynamically per user session. Even on a shared public SSID, each user session is individually encrypted with AES-GCMP or AES-CCMP.

Benchmark your staff WiFi network

Use our free assessment to see how your network compares against Purple's Bronze, Silver and Gold tiers - and get a personalised report your IT team can use to plan the next upgrade.

Get the free WiFi benchmark

Ready to get started?

Book a demo with one of our experts to see how Purple can help you achieve your business goals.

Speak to an expert