- Home
- WiFi Glossary
- WPA-Enterprise
What is WPA-Enterprise?
Definition
WPA-Enterprise is WiFi Protected Access running in 802.1X mode: each user or device authenticates against a RADIUS server with its own credential, instead of sharing one network password. WPA2-Enterprise and WPA3-Enterprise are successive versions, and WPA3-Enterprise is the current standard for new deployments.
WPA-Enterprise explained
WPA comes in two modes. Personal mode uses a pre-shared key that everyone types, which is simple but cannot tell users apart. Enterprise mode replaces that key with 802.1X authentication through RADIUS, so each session belongs to a named user or device, gets its own encryption keys and can be revoked on its own.
The credential is set by the EAP method. EAP-TLS uses certificates and is the strongest option. PEAP uses a username and password inside a TLS tunnel. The RADIUS server can also return attributes that place the user on a specific VLAN, so one SSID can serve several roles.
WPA3-Enterprise closes weaknesses in WPA2-Enterprise and, in its highest security mode, requires 192-bit cryptographic strength using GCMP-256 encryption. It is required for WiFi 6 and WiFi 6E certified equipment and is the recommended minimum for corporate, healthcare and financial networks. Legacy devices that cannot support it are usually moved to their own SSID during a phased migration rather than holding the whole network back.
Guides on WPA-Enterprise
- Technical guideWPA3-Enterprise: a deployment guide
- Technical guideWPA2 vs 802.1X: what’s the difference?
- Technical guideWPA, WPA2 and WPA3: what’s the difference and which should you use?
Where it fits
Related terms
Need more than a definition?
Talk to our team about how Purple combines guest WiFi, captive portals, RADIUS, and analytics into a single platform that runs on the access points you already own.