Skip to main content

Technical WiFi guides

Deep, expert-led technical guides on guest WiFi, analytics, captive portals, and venue technology.

Ready to move from research to rollout? See how Purple's captive portal software handles branded guest sign-in, analytics, and compliance in one platform.

How to revoke WiFi access when an employee leaves
Enterprise WiFi Security

How to revoke WiFi access when an employee leaves

This guide shows IT and venue operations teams how to remove Staff WiFi access when an employee leaves without disrupting the rest of the workforce. It compares certificate-based 802.1X, identity-specific iPSK and SCIM-driven deprovisioning, then provides a same-day runbook, test method and audit evidence model.

12 mins read3k words
Enterprise WiFi Security

Secure BYOD WiFi: Passpoint certificate onboarding vs xPSK (iPSK)

A comprehensive technical guide for IT teams on securing unmanaged employee and student devices (BYOD) using zero-touch Passpoint EAP-TLS certificates vs vendor-specific xPSK (iPSK/easyPSK, DPSK, PPSK, MPSK).

5 mins read1k words
WPA2 Personal vs Enterprise: what is the difference and which should you use?
Enterprise WiFi Security

WPA2 Personal vs Enterprise: what is the difference and which should you use?

This technical reference guide provides a comprehensive comparison of WPA2 Personal and WPA2 Enterprise security protocols within enterprise WiFi environments. It outlines the architectural differences, deployment methodologies, and security implications of each standard to help network architects and IT leaders make informed deployment decisions.

9 mins read2k words
Three SSIDs to rule them all: guest, Passpoint, and IoT WiFi setup guide
Enterprise WiFi Security

Three SSIDs to rule them all: guest, Passpoint, and IoT WiFi setup guide

This technical guide provides a definitive blueprint for implementing the three-SSID WiFi design across enterprise venues. It details the configuration of an open Guest WiFi portal, automated Passpoint onboarding, and per-device xPSK authentication to achieve complete VLAN segmentation and zero-trust network access.

5 mins read1k words
Enterprise WiFi authentication without Active Directory or an on-prem server
Enterprise WiFi Security

Enterprise WiFi authentication without Active Directory or an on-prem server

This guide explains how to deploy secure WPA2/3-Enterprise WiFi authentication without an on-premises Active Directory, Windows NPS, or RADIUS server. It covers the protocol mismatch between cloud identity providers and 802.1X, the case for EAP-TLS over PEAP-MSCHAPv2, and how to deploy cloud RADIUS with MDM-issued certificates against Microsoft Entra ID, Okta, or Google Workspace. Written for IT leads at cloud-first and Mac/Chromebook-heavy organisations that are ready to retire on-premises infrastructure.

9 mins read2k words
Google Workspace WiFi Authentication: Chromebook and LDAP Integration
Enterprise WiFi Security

Google Workspace WiFi Authentication: Chromebook and LDAP Integration

A definitive technical reference for IT administrators deploying secure WiFi in Google Workspace environments. This guide covers 802.1X certificate deployment to managed Chromebooks via Google Admin Console, Google Secure LDAP integration as a RADIUS backend, and architecture decisions for education, media, and enterprise venues. It provides actionable implementation steps, real-world case studies, and a direct comparison of EAP methods to help teams move from vulnerable shared PSKs to robust, identity-based network access control.

8 mins read2k words