Skip to main content
Staff WiFi
Passwordless

The authenticator app for WiFi

Most staff WiFi networks run on a shared password. Written on whiteboards, shared in Slack channels, and never changed when people leave.

Purple gives you proper enterprise security without the hassle. Staff log in to our Purple authenticator app with their existing Microsoft, Google, or Okta credentials, and get online automatically. Done.

  • WPA2/3-Enterprise encryption
  • Works with Microsoft Entra ID, Okta, and Google Workspace
  • When staff leave the company, their access stops
  • Runs on Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, and Ubiquiti UniFi
IT and Network
Security

Proper security, not security theater

Each user gets their own encryption keys. Even on the same access point, one user can't sniff another's traffic. Remove someone from your directory and Purple drops their WiFi access within minutes. No tickets to raise. No passwords to change.

Every connection is logged: who connected, when, from which device, at which location. When the auditors ask, you have answers.

  • Unique session keys per user
  • Automatic revocation via SCIM
  • Full audit trail
  • ISO 27001 certified
Staff WiFi
Onboarding

60 seconds to connected

Staff download the Purple app, tap "Sign in with Microsoft" (or Google, or Okta), and tap to install their WiFi pass. Done. Works on Windows, macOS, Linux, iOS, and Android.

No more walking people through WiFi settings over the phone. No more password resets. IT teams using Purple typically see WiFi support tickets drop by 80%.

  • SSO login (no new credentials)
  • One-tap profile installation
  • Automatic connection (no repeated logins)
  • Works across all your locations
Cost Effective
Scalable

Runs 80,000+ venues. Yours won't break it.

Purple's authentication infrastructure has been running for over a decade. Airports, banks, retailers, universities. 400 million+ users. No on-prem servers for you to maintain. Just point your access points at our RADIUS and you're done.

  • 80,000+ venues live
  • 400M+ users
  • 99.999% uptime
Staff WiFi
Analytics

See who's actually in the office

Staff WiFi data tells you which days are busy, which floors are empty, and whether your hybrid working policy is actually working. Export the data to your facilities team or plug it into your existing dashboards.

  • Occupancy by day/hour/department
  • Hybrid work pattern analysis
  • Building utilization reports
  • Exportable data
Untitled design

Headquarters

Your main office needs the tightest security. Staff authenticate via SSO and land on the right VLAN based on their role. Contractors get time-limited access that expires automatically.

  • Role-based VLAN assignment
  • Contractor access management
  • Full audit trail
ConneX Square

Branch offices

Roll out the same security across every location without shipping hardware. Staff profiles work everywhere. When someone visits a different office, their device connects automatically.

  • Centralized policy management
  • No on-site RADIUS servers
  • Consistent experience everywhere
Untitled design

Hybrid workers

When staff work from client sites or coworking spaces that run Purple, their device connects automatically. No hunting for passwords. No filling in captive portal forms.

  • OpenRoaming support
  • Automatic connection at partner sites
  • Same security everywhere
Staff WiFi Page

Staff engagement

The Purple app turns your staff WiFi from a connection into a two-way channel. Reach employees on the device they already use to get online.

  • Run surveys for real-time and anonymous feedback
  • Deliver content by role, location, or time
  • Send staff straight to internal resources or training portals

Add Shield to cut bandwidth and distractions

Staff WiFi keeps your people connected. Shield keeps the connection clean. It filters at the DNS layer, so there’s no extra hardware to buy and no firewall to change, and it rolls out across your whole estate in minutes.

Reclaim your bandwidth

Shield strips ads, trackers, and bloatware before they load, and can throttle high-bandwidth streaming during busy periods. Pages pull up to 44% less data and fire 62% fewer DNS queries, leaving headroom for the traffic that runs your business.

Remove the distractions

Ad and tracker blocking means staff pages load up to 53% faster and arrive clean. Set policies by site, department, or time of day to keep people focused and keep content you don’t want off a work network.

53%
faster page loads
44%
less data used
62%
fewer DNS queries

The Staff WiFi Standard for IT Leaders

A practical benchmark for evaluating, deploying, and managing enterprise staff WiFi - written for IT decision makers.

The Staff WiFi Standard for IT Leaders

See how staff wifi works in venues like yours, and how Purple compares to alternatives.

Frequently Asked Questions

What is staff WiFi and how is it different from guest WiFi?

Staff WiFi is an employee-only wireless network authenticated per-user, isolated from the guest and payment networks. Where guest WiFi optimises for low-friction sign-up, staff WiFi optimises for identity — each employee authenticates with their own credential (certificate, password, or iPSK) via 802.1X against a RADIUS server, and their access can be revoked the moment they leave the company without touching anyone else on the network.

What authentication does Purple staff WiFi use?

WPA2-Enterprise or WPA3-Enterprise with 802.1X. The standard options are EAP-TLS (certificate-based, the gold standard for managed laptops), PEAP (username + password for legacy devices), and iPSK (unique per-device pre-shared key for BYOD and IoT). Authentication runs against your identity provider — Microsoft Entra ID, Okta, Google Workspace, or any SAML 2.0 IdP.

Do I need my own RADIUS server?

No. Purple operates the RADIUS server as a cloud service - RADIUS-as-a-Service - with multi-region failover and a 99.999% uptime SLA. Your access points point at Purple, Purple validates credentials against your identity provider, and no one in your team operates RADIUS infrastructure. If you already run FreeRADIUS, NPS, or Cisco ISE, migration is a weekend exercise.

How does Purple staff WiFi integrate with Entra ID, Okta, or Google Workspace?

Directly via SAML and SCIM. When an employee is added to the IdP, their WiFi access is provisioned automatically; when they leave, access is revoked at the same moment their email is revoked. Group membership in the IdP drives VLAN policy — marketing, engineering, and contractors can each land on their own network segment without manual configuration.

Does Purple support employee WiFi for BYOD and IoT devices?

Yes. BYOD onboarding uses certificate enrolment via an MDM (Intune, Jamf, Kandji, Hexnode) for managed devices, or a self-service portal for unmanaged phones and tablets. IoT devices — printers, access controllers, smart lighting — typically use iPSK (Identity PSK) on a dedicated SSID so each device has a unique key you can revoke without affecting others.

Can I revoke one employee's WiFi access without disrupting others?

Yes, instantly. Because staff WiFi is per-user, disabling the employee in your identity provider revokes their WiFi access at the next authentication attempt. Compare this to a shared WiFi password, where one departing employee forces a company-wide password rotation. This is the single biggest operational reason to move from WPA-Personal to WPA-Enterprise.

Does Purple staff WiFi work with my existing access points?

Yes. Purple runs on any enterprise-grade access point that speaks RADIUS — Cisco Meraki, Cisco Catalyst, Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme, Fortinet FortiAP, and more. You do not replace hardware; you reconfigure SSIDs to authenticate via Purple.

How does staff WiFi handle Conditional Access and Zero Trust?

Purple respects Conditional Access policies from Entra ID — a device that fails compliance checks is not admitted to the network. For broader Zero Trust postures, Purple emits every authentication event to SIEM (Microsoft Sentinel, Splunk, Elastic, Datadog) via webhook or syslog, so network access becomes a signal in your broader security analytics.