Skip to main content

The death of the captive portal: why Apple, Google, and Samsung are phasing out legacy guest WiFi

Iain JewittBy Iain Jewitt
24 November 2025
6 min read
The death of the captive portal: why Apple, Google, and Samsung are phasing out legacy guest WiFi
Interactive IT Network Diagnostic

Captive portal vs Passpoint readiness simulator

Test how modern operating systems (Apple iOS, Android 15, Samsung One UI) interact with your guest WiFi architecture and uncover why legacy splash screens are failing.

⚠️ Friction & Failure Prone

Apple iOS & iPadOS on Legacy Open SSID + HTTP Redirection

Probe: http://captive.apple.com/hotspot-detect.html
CNA Sheet & Browser Behavior

Launches sandboxed Captive Network Assistant (CNA) web sheet without shared Safari cookies, passkey autofill, or external OAuth redirect support.

MAC Randomization & CRM Impact

Rotates private Wi-Fi address per SSID and periodically under iOS 18 Private MAC rules, breaking 24-hour MAC-based CRM re-identification.

Encrypted DNS & DoH Vulnerability

iCloud Private Relay and DoH encrypt upstream queries; HTTP 302 hijacking triggers connection timeouts or security alerts.

Protocol ArchitectureUser Onboarding ExperienceSecurity & EncryptionReturning Guest Recognition
Legacy Open SSID + HTTP RedirectionHigh friction. User connects, waits for CNA popup or opens browser, manually enters credentials.Critical Risk (Vulnerable to Evil Twin, eavesdropping, and MitM packet sniffing).Poor (0% return recognition due to MAC randomization).
⚙️ Network Controller Blueprint (MERAKI)
# Next-Gen Guest WiFi Migration Blueprint: Apple iOS & iPadOS
# Hardware Target: MERAKI Enterprise Infrastructure
# Target Architecture: Legacy Open SSID + HTTP Redirection

[1] CAPTIVE PROBE HANDLING
 - Client Probe Target: http://captive.apple.com/hotspot-detect.html
 - Recommended Probe Response: Migrate from HTTP 302 to RFC 8908 DHCP Option 114

[2] ENCRYPTION & SECURITY
 - WPA Mode: WPA2/WPA3-Personal with OWE (Opportunistic Wireless Encryption)
 - Client Isolation: Enabled on all guest VLANs (block inter-station traffic)
 - Peer-to-Peer Blocking: Enforce RFC 1918 subnet isolation at default gateway

[3] PRIVATE DNS & MAC RANDOMIZATION MITIGATION
 - Private DNS Policy: WARNING: DoH/DoT will bypass legacy DNS interception. Deploy RFC 8908 API.
 - Identity Resolution: Transition from ephemeral MAC tracking to Passpoint cryptographic token or verified captive OAuth profile

[4] PURPLE PLATFORM OVERLAY
 - Seamless integration with existing APs without replacing controllers
 - Certified ISO 27001 & GDPR-compliant first-party data capture engine
 - Automated migration roadmap to zero-touch Passpoint / OpenRoaming

Eliminate captive portal friction with Purple Passpoint & API Overlay

Purple overlays seamlessly onto your existing Cisco Meraki, Aruba, Ruckus, or UniFi controllers. Transition smoothly from legacy splash pages to encrypted, zero-touch Passpoint without replacing hardware.

Explore Guest WiFi

If you manage guest WiFi for a physical venue, your relationship with the captive portal is undergoing a fundamental shift. For years, the browser splash page served as the digital front door for public networks. Purple spent over a decade refining that onboarding experience for enterprise venues worldwide.

However, major mobile operating system vendors are actively deprecating legacy captive portals in favor of seamless, encrypted network onboarding standards.

The pop-up web portal is changing from an industry standard into an operational constraint. For IT directors, network architects, and venue operators, preparing for passwordless, automated WiFi access is now essential. Explore our comprehensive captive portal guide for full architectural context.

Why mobile OS vendors are targeting legacy captive portals

Apple, Google, and Samsung control the primary mobile operating systems. To deliver smoother and more secure mobile experiences, these vendors are systematically restricting legacy captive portal behavior across recent OS releases.

Web pop-up portals represent friction, security vulnerabilities, and unpredictable connection failures for mobile users. Three key technical factors drive this architectural shift:

  • Sandboxed Captive Network Assistants (CNAs): Operating systems launch lightweight web views to display splash pages. To protect device security, vendors restrict these mini-browsers by blocking persistent cookies, preventing password manager integration, and disabling complex multi-factor authentication (MFA) flows.
  • Private MAC Address Randomization: Modern devices rotate MAC addresses per network or per session. Legacy captive portals that rely on un-randomized MAC addresses for session tracking fail to recognize returning guests, forcing users through repetitive login screens.
  • Phishing and Evil Twin Vulnerabilities: Unencrypted open WiFi networks displaying unauthenticated web forms expose users to man-in-the-middle attacks. Security guidelines recommend encrypted link-layer authentication over open web forms. Learn more in our enterprise WiFi security guide.

Comparing legacy captive portals with Passpoint and OpenRoaming

Transitioning from browser splash pages to automated network authentication improves security, guest satisfaction, and network management:

Feature / Metric Legacy Captive Portal Passpoint (Hotspot 2.0) WBA OpenRoaming
Authentication Method Web browser pop-up form WPA3 / 802.1X enterprise profile Global federated identity profile
User Login Friction High (Manual web inputs per session) Zero (Instant background connection) Zero (Instant global roaming)
Over-the-Air Encryption None (Open unencrypted network) Enterprise WPA3 / AES encryption Enterprise WPA3 / AES encryption
MAC Randomization Resilience Low (Forces re-authentication) High (Uses certificate/ANQP credentials) High (Uses federated Passpoint profile)
Guest Return Rate Accuracy Degraded by private MAC rotation 100% accurate device identification 100% accurate device identification
Hardware Compatibility Standard open SSID hardware 802.11u enterprise access points Passpoint Release 2/3 certified APs

How Passpoint and OpenRoaming replace legacy splash screens

Passpoint (based on the WiFi Alliance Hotspot 2.0 specification and IEEE 802.11u) enables mobile devices to discover, select, and authenticate with WiFi networks automatically. Once a user installs a secure Passpoint profile, their device connects whenever they enter venue coverage.

OpenRoaming, led by the Wireless Broadband Alliance (WBA), extends Passpoint into a global federation. Devices with an OpenRoaming profile connect automatically across participating airports, venues, retail locations, and transit hubs. Purple operates as a certified OpenRoaming identity provider, allowing venues to offer instant onboarding while maintaining compliance and access control.

Transitioning to automated background connection provides distinct advantages:

  • Enhanced link-layer encryption: Passpoint secures data over the air using WPA3 Enterprise encryption, protecting guest traffic from interception on public networks.
  • Passwordless user experience: Guests avoid filling out web forms or searching for network passwords, receiving connectivity identical to cellular roaming.
  • High-quality customer engagement: Rather than forcing data entry before granting internet access, venues engage guests post-connection via app notifications, web redirects, or opted-in CRM communications. Read details in our WiFi marketing guide and WiFi analytics guide.

Implementation steps for venue operators

  1. Audit existing wireless infrastructure: Purple overlays existing access points from Cisco Meraki, HPE Aruba, Ruckus, Ubiquiti UniFi, and Juniper Mist without requiring hardware replacements.
  2. Enable Passpoint (802.11u) SSIDs: Configure your enterprise wireless LAN controller to broadcast Passpoint ANQP profiles alongside legacy SSIDs during the transition phase.
  3. Deploy cloud RADIUS authentication: Route Passpoint authentication requests to Purple cloud RADIUS servers to handle certificate management and profile provisioning.
  4. Provide profile provisioning: Allow guests to onboard via a one-click profile download link on your website, app, or email invitation.

Frequently asked questions about captive portal deprecation

Are captive portals being completely phased out by Apple and Google?

Apple and Google are restricting Captive Network Assistants (CNAs) through sandboxing, cookie blocking, and MAC address randomization. While web splash pages still function for simple click-through access, OS vendors prioritize automated Passpoint and OpenRoaming profiles for secure, frictionless connection.

How does Passpoint differ from a traditional captive portal?

Traditional captive portals require manual web browser form submission on open, unencrypted WiFi networks. Passpoint (Hotspot 2.0) authenticates devices automatically using enterprise WPA3 encryption without requiring web page interaction.

What is OpenRoaming and how does it benefit venue operators?

OpenRoaming is a global federation established by the Wireless Broadband Alliance. It enables venue visitors to connect automatically across thousands of participating networks using a single secure profile, eliminating login friction while preserving venue analytics.

Do I need to replace my existing WiFi hardware to support Passpoint?

No. Most enterprise access points from Cisco Meraki, HPE Aruba, Ruckus, Ubiquiti UniFi, and Juniper Mist support 802.11u and Passpoint via software configuration. Purple overlays your current hardware seamlessly.

Frequently asked questions

Why are Apple, Google, and Samsung restricting legacy captive portals?

Mobile operating systems (iOS 18, Android 15, Samsung One UI) treat legacy captive portals as security risks and user friction. Unencrypted HTTP redirects, DNS hijacking, and sandboxed mini-browsers (Captive Network Assistant) break modern privacy safeguards like Apple Private Relay, Android Private DNS (DoT), and passkeys. As a result, operating systems are transitioning toward standardized RFC 8908 Captive Portal APIs and encrypted Passpoint (Hotspot 2.0) profiles.

How does MAC address randomisation impact captive portal guest tracking?

Modern smartphones generate randomized MAC addresses per SSID and rotate them periodically. Because legacy captive portals rely on the physical MAC address to remember returning visitors, randomized MACs break return-guest recognition, causing repeated login friction and fragmenting CRM analytics. Passpoint and authenticated OAuth tokens resolve this by binding guest identity to secure cryptographic certificates rather than ephemeral hardware addresses.

What is the RFC 8908 / RFC 8910 Captive Portal API?

RFC 8908 and RFC 8910 define an IETF standard where the network gateway advertises a JSON API endpoint via DHCP Option 114 or IPv6 Router Advertisements. Instead of intercepting web traffic with brittle DNS spoofing or HTTP 302 redirects, the client operating system queries the API directly over HTTPS to check captive status, session expiration, and venue terms securely without browser warnings.

What is Passpoint (Hotspot 2.0) and how does it replace captive portals?

Passpoint (IEEE 802.11u) enables smartphones and laptops to automatically discover and connect to enterprise guest WiFi networks with zero manual intervention. Using WPA2/WPA3-Enterprise 802.1X encryption and EAP-TLS/EAP-TTLS certificates, Passpoint eliminates web splash screens entirely, protects data against eavesdropping, and connects returning visitors instantly across thousands of global venues.

Can venues still collect first-party marketing data without a traditional splash screen?

Yes. With Passpoint and modern onboarding workflows, guests authenticate once via a secure web portal, app, or SMS OTP to install an encrypted Passpoint profile. All subsequent visits connect automatically in the background while syncing attendance, dwell time, and demographic data directly to enterprise CRM platforms like HubSpot and Salesforce in full compliance with GDPR and CCPA.

Does transitioning away from legacy captive portals require replacing access point hardware?

No. Modern solutions like Purple integrate as a software overlay on existing enterprise wireless hardware from Cisco Meraki, HPE Aruba Networking, CommScope Ruckus, Juniper Mist, and Ubiquiti UniFi. Venues can support RFC 8908 APIs and Passpoint alongside branded splash pages without buying new controllers or access points.

Ready to get started?

Book a demo with one of our experts to see how Purple can help you achieve your business goals.

Speak to an expert