Skip to main content

Portnox Alternatives: Cloud RADIUS Without the Full NAC

You will be able to decide whether your estate needs full NAC or only cloud RADIUS for WiFi, using a three-question test. You can then compare Portnox, Purple, SecureW2 and JumpCloud on wired enforcement, posture checks, certificates, guest access and three-year running cost, and plan a site-by-site pilot.

By Iain JewittPublished
📖 13 min read2,928 words3 worked examples12 key definitions

Part of our core series: Enterprise WiFi Security Guide →

For organizations seeking Portnox alternatives to secure WiFi without full network access control, cloud RADIUS using the IEEE 802.1X standard is the answer. Platforms like Purple integrate with Microsoft Entra ID to authenticate users across more than 80,000 venues, eliminating complex posture checks while maintaining secure staff and guest access.

Do you need full NAC or just cloud RADIUS for WiFi?

Start with the job, not the vendor. Two layers get bundled together in sales conversations, and they solve different problems.

What cloud RADIUS does

RADIUS, defined in IETF RFC 2865, is the protocol your access points use to ask whether a device may join. IEEE 802.1X is the port-based access control standard that carries that request. It runs between the device, the access point or switch, and the RADIUS server. Cloud RADIUS hosts that server as a service, so you run no appliance on site.

A cloud RADIUS service checks an identity against your directory and returns a decision. It can also return a VLAN, a separate logical network segment, so staff, guests and devices stay isolated. That covers most WiFi authentication needs.

What NAC adds on top

A NAC platform does more than say yes or no. It discovers devices across wired, wireless and VPN connections. It assesses posture, meaning whether a device meets your security baseline before it connects. It then quarantines or remediates devices that fail. Portnox Cloud bundles this with its own cloud RADIUS service, according to Portnox's product documentation.

The three-question test

Three questions separate the two requirements:

  1. Must you stop unknown devices plugging into wired switch ports?
  2. Must you check a laptop's patch level, antivirus or disk encryption before it connects?
  3. Does an auditor or insurer require one access policy across wired, wireless and VPN?

If you answer no to all three, you need cloud RADIUS. If you answer yes to the first two, NAC earns its cost. If your wired estate is fixed registers, printers and access points in locked IT closets, question one often answers itself.

Where Portnox, Purple, SecureW2 and JumpCloud genuinely differ

All four authenticate devices using 802.1X and RADIUS. The differences sit in what surrounds that core: wired enforcement, posture checks, certificates and guest access.

Portnox Purple SecureW2 JumpCloud
Primary category Cloud-native NAC with built-in cloud RADIUS Guest and staff WiFi platform with cloud RADIUS Cloud RADIUS and managed PKI Directory and device management platform with cloud RADIUS
Wired 802.1X port control Yes, a core feature No, WiFi-focused Yes, wired and wireless Documented for WiFi and VPN
Endpoint posture checks Yes, agent-based risk assessment No Policy lookups against identity provider and MDM No dedicated posture engine
Staff WiFi methods 802.1X, MAC authentication bypass 802.1X, iPSK, SecurePass EAP-TLS certificates, PEAP 802.1X against directory credentials or certificates
Identity providers Microsoft Entra ID, Okta, Google Workspace Microsoft Entra ID, Okta, Google Workspace Microsoft Entra ID, Okta, Google Workspace JumpCloud directory, synced from Microsoft Entra ID or Google Workspace
Hardware Any 802.1X-capable switch or access point Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme, Fortinet Any 802.1X-capable switch or access point Any 802.1X-capable access point
Best fit Mixed wired and wireless estates with managed laptops Venues running guest and staff WiFi together IT teams standardizing on certificates Organizations already using JumpCloud as their directory

A few terms need defining. EAP-TLS, specified in RFC 5216, authenticates a device with a digital certificate instead of a password. PEAP wraps a username and password exchange inside an encrypted tunnel. iPSK, or identity pre-shared key, gives each person or device its own WiFi key on a single network name. MAC authentication bypass, or MAB, admits devices that cannot run 802.1X based on their hardware address. Public key infrastructure, or PKI, is the system that issues and revokes those certificates.

When is Portnox the right call?

Portnox earns its place when access control must reach beyond WiFi. Its documentation covers wired, wireless and VPN access control and endpoint risk assessment. It also covers TACACS+, the protocol that controls administrator logins to switches and routers. If you need all of that from one console, a bundle makes sense.

Where Portnox excels

  • Wired port enforcement. An unknown laptop plugged into a meeting room port gets blocked or quarantined.
  • Posture before access. Managed laptops must pass health checks before reaching sensitive systems.
  • One policy plane. Wired, wireless and VPN rules live in a single place, which simplifies audit evidence.
  • Device administration. TACACS+ governs who can change switch and router configurations.

Healthcare and public sector estates often fit this profile. Clinical and office networks mix managed laptops, wired desks and remote access. See how Purple approaches Healthcare venues, where patient and visitor WiFi still sits alongside clinical networks.

Where Portnox overreaches for venue WiFi

If your problem is WiFi onboarding, a NAC bundle brings costs you will not use. Posture agents need deploying and maintaining on every managed device. Wired enforcement needs switch configuration at every site. None of that improves the guest login at a hotel, store or stadium. Portnox also does not position itself as a guest WiFi platform. If you need a captive portal, marketing consent and visit data, you will buy a second product. A captive portal is the web page a visitor sees before WiFi access is granted.

Worked scenario: a county or municipal government

Situation. A regional government ran 12 office buildings and nine libraries. It had 600 wired desk ports, 1,100 managed laptops and a VPN for remote work. Its insurer asked for evidence that unknown devices could not reach the corporate network.

What was done. The government deployed NAC across wired, wireless and VPN, with posture checks on managed laptops. Library visitor WiFi moved to a separate guest SSID on its own VLAN, outside NAC scope.

Outcome. Three separate access policies, for wired, wireless and VPN, became one. All 600 desk ports moved under enforcement. Visitor devices stayed out of the NAC license count entirely. This modeled scenario shows the point: buy NAC where the wired and posture requirement exists, not for visitor WiFi.

When is cloud RADIUS without the NAC the right call?

Cloud RADIUS wins when WiFi is the estate you need to secure. You keep 802.1X and VLAN segmentation without agents, posture engines or wired rollout. The three alternatives suit different starting points.

Purple: guest and staff WiFi on one platform

Purple is a cloud overlay that layers on top of your existing infrastructure. It is hardware-agnostic, running on Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. No rip and replace is required.

For staff, Purple's Identity-Based Networks authenticate against Microsoft Entra ID, Okta or Google Workspace. When HR disables a leaver in the directory, their WiFi access goes with it. That handles joiners, movers and leavers without rotating a shared password. SecurePass, Verify and Shield are security add-ons on top of the Connect, Capture and Engage plans.

For guests, Purple runs the captive portal, conscious-choice opt-ins and first-party data capture on the same platform. Captive portals have one known quirk. If a visitor misses the login prompt, an HTTPS page cannot be redirected cleanly, so the browser shows a certificate warning. Purple's support article "Connection Error" explains the cause and the workaround. OpenRoaming and Passpoint (also called Hotspot 2.0) remove the portal step by letting devices join securely and automatically.

Purple's scale is its own evidence. We have run since 2012 across 80,000+ live venues, with 440 million logins in 2024. Purple reports 99.999% uptime and holds ISO 27001, Cyber Essentials and B Corp certification. The platform is CCPA/CPRA and GDPR compliant.

SecureW2: certificate-first authentication

SecureW2 combines cloud RADIUS with managed PKI, according to its product documentation. Its JoinNow onboarding client installs certificates on devices so they authenticate with EAP-TLS. That removes passwords from WiFi authentication altogether. It suits IT teams with managed device fleets who want certificates everywhere, including wired 802.1X, without full NAC.

JumpCloud: RADIUS as part of the directory

JumpCloud includes cloud RADIUS within its directory platform. Staff authenticate to WiFi with the same identity they use for everything else in JumpCloud. If JumpCloud already runs your directory, adding RADIUS involves no new vendor and no new identity source.

Worked scenario: a 30-hotel group

Situation. A hotel group ran Cisco Meraki access points across 30 hotels. Staff WiFi used one shared password per hotel. A Portnox quote covered 4,500 endpoints, including wired cash registers, printers and back-office PCs. The actual requirement was 1,800 staff devices joining WiFi, plus guest access.

What was done. The group kept wired cash registers on a segmented VLAN managed at the switch. Staff WiFi moved to identity-based 802.1X against Microsoft Entra ID. Guest WiFi moved to a captive portal with opt-in consent on the same platform.

Outcome. The licensed scope fell from 4,500 endpoints to the 1,800 staff devices that actually join WiFi. Thirty shared hotel passwords were retired, so a leaver no longer forces 30 password changes. Guest access and staff authentication now run from one console instead of two products. This is a modeled scenario, with outcomes calculated from its own inputs. Read more on Hotels.

Got questions about your specific setup?

Our team works with venue operators, IT managers, and network engineers across 80,000 venues. Book a 20-minute call and we will show you how others like you solved it.

What about wired NAC needs?

Wired requirements are the main reason teams look at Portnox. Before you buy a NAC to cover them, test whether you need posture or only authentication.

Option 1: segment the wired estate at the switch

Fixed devices such as cash registers, kitchen printers and access points rarely move. Put them on dedicated VLANs with switch-level port security. PCI DSS, published by the PCI Security Standards Council, treats network segmentation as a way to reduce cardholder data scope. Many retail and hospitality estates meet their wired requirement this way.

Option 2: wired 802.1X with cloud RADIUS

If you want wired authentication without posture checks, use a cloud RADIUS service that supports wired 802.1X. SecureW2 documents this. You get identity on every port without agents or a NAC license. Devices that cannot run 802.1X fall back to MAB.

Option 3: NAC for wired, cloud RADIUS for WiFi

Some estates need posture on head-office desks but not at venues. You can scope NAC to head office and run venue WiFi on a separate cloud RADIUS platform. This split keeps the NAC license count small. It also stops guest devices inflating your endpoint numbers.

Option 4: full NAC everywhere

Choose this when posture checks on wired, wireless and VPN are a hard requirement. Government networks handling sensitive data and clinical networks often land here. NIST SP 800-207, the US zero trust architecture guidance, describes continuous device assessment of the kind NAC provides.

What does each option cost to run?

License price is only one line. Agents, certificates, switch work and a second guest platform add cost over a three-year term. Compare these drivers before you compare quotes.

Cost driver Portnox Purple SecureW2 JumpCloud
License model Quote-based subscription Connect, Capture or Engage plan, plus SecurePass, Verify or Shield add-ons Quote-based subscription Published per-person monthly packages
On-site appliance None required None required None required None required
Endpoint agent Agent for posture checks None JoinNow client for certificate onboarding JumpCloud agent if you use its device management
Certificates and PKI Built-in certificate authority Not required for iPSK Managed PKI is the core product Directory credentials, certificate option available
Separate guest WiFi platform Required Included Required Required
Wired rollout effort Switch configuration at every site None, WiFi only Switch configuration where wired 802.1X is used None for WiFi-only use

Questions to put to every vendor

  • Does the license count wired, wireless and VPN endpoints together, or separately?
  • Are guest and visitor devices counted toward the license?
  • Who deploys and maintains the endpoint agent, and on how many devices?
  • What happens to authentication if the cloud service is unreachable?
  • Which access point and switch vendors are tested and supported?

Where hidden costs hide

The biggest hidden cost is the second product. If your NAC or RADIUS vendor does not run guest WiFi, you buy and integrate a captive portal separately. You then manage two consoles, two contracts and two support routes. Guest WiFi also feeds visit data. If that matters, read Presence analytics vs engagement analytics.

The second hidden cost is agent maintenance. Every operating system update can break an agent. Factor support hours into your total cost of ownership, not only license fees.

How to decide for your estate

Map your situation to a recommendation. The matrix below covers the patterns IT and venue operations teams raise most when evaluating Portnox alternatives.

Your situation Recommendation Why
Wired desks, managed laptops, posture required by auditor Portnox Posture and wired enforcement are the requirement
Hotels, stores or venues needing guest and staff WiFi Purple One platform for captive portal and identity-based staff WiFi
Managed fleet, certificates wanted on wired and wireless SecureW2 Managed PKI with EAP-TLS, no posture engine
JumpCloud already your directory, WiFi-only need JumpCloud RADIUS from the identity source you already run
Head office needs posture, venues need WiFi Portnox at head office, Purple at venues NAC scoped to where posture matters
Fixed wired devices only, card payments in scope Switch VLAN segmentation plus cloud RADIUS for WiFi Segmentation reduces PCI-DSS scope without NAC

Worked scenario: a 120-store retail chain

Situation. A retailer ran 120 stores, each with staff handhelds and cell phones on WiFi. Registers were wired on a separate network. The IT team already used JumpCloud as its directory and was evaluating Portnox for staff WiFi.

What was done. The team applied the three-question test. Wired registers were already segmented, posture checks were not required, and no auditor asked for a unified policy. Staff WiFi moved to 802.1X against the existing directory. Shopper WiFi ran separately with its own captive portal.

Outcome. The team avoided rolling a posture agent to 1,400 handhelds and cell phones. It retired 120 shared store passwords. A leaver now loses WiFi access in every store when their directory account is disabled. This is a modeled scenario. See how Purple supports Retail estates.

A sensible order of work

  1. List every device type and whether it connects wired, wireless or both.
  2. Run the three-question test for each site type, not the estate as a whole.
  3. Price NAC only for the sites and devices that need posture.
  4. Price cloud RADIUS for everything else, including guest WiFi.
  5. Pilot one site, one SSID at a time, before you commit across the estate.

Transport follows the same logic. Rail operators including c2c Rail and Avanti West Coast run passenger WiFi on Purple, where onboard posture checks make no sense. See Trains.

Frequently asked questions

Is Purple a direct replacement for Portnox?

No, not for every Portnox use case. Purple replaces Portnox where your requirement is WiFi authentication for staff and guests. Purple does not offer wired port enforcement or endpoint posture checks. If you need those, keep a NAC for the wired and managed-laptop estate. Run Purple for venue WiFi, where it also provides the captive portal, conscious-choice opt-ins and WiFi analytics that Portnox does not position itself to deliver.

Can I run cloud RADIUS for WiFi and keep a NAC for wired ports?

Yes, and many estates should. Scope the NAC to sites and devices that need posture checks, such as head office desks and managed laptops. Run venue and guest WiFi on a separate cloud RADIUS platform. This keeps guest devices out of your NAC license count. It also avoids deploying posture agents to handhelds and cell phones that never touch sensitive systems.

Does Purple work with the access points I already own?

Yes. Purple is hardware-agnostic and runs as a cloud overlay on Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. No rip and replace is required. You point your access points at Purple for authentication and the captive portal, and your existing wireless network keeps running underneath.

How do I migrate staff WiFi from Portnox to cloud RADIUS?

Migrate one SSID and one site at a time. Create the new staff network alongside the existing one, authenticated against Microsoft Entra ID, Okta or Google Workspace. Move a pilot group, confirm VLAN assignment and roaming, then expand. Leave wired enforcement on Portnox until you have decided whether wired posture is still a requirement. Retire the old SSID only once every device has moved.

Is cloud RADIUS without NAC enough for PCI DSS?

Yes, for many card-accepting venues, provided payment systems are segmented. PCI DSS treats network segmentation as a way to reduce the scope of cardholder data environments. Keep registers and payment devices on isolated wired VLANs. Run staff and guest WiFi on separate segments authenticated through cloud RADIUS. Confirm your segmentation design with your Qualified Security Assessor before you rely on it.

Is SecureW2 or JumpCloud cheaper than Portnox?

Usually yes for WiFi-only needs, because you avoid paying for unused NAC features. JumpCloud publishes per-person monthly packages with RADIUS in selected tiers. SecureW2 and Portnox quote per deal. Compare total cost, not license price. Include agent maintenance, certificate management, switch configuration and a separate guest WiFi platform, which all three require and Purple includes.

Does cloud RADIUS handle leavers automatically?

Yes, when it authenticates against your identity provider. Purple's Identity-Based Networks check staff against Microsoft Entra ID, Okta or Google Workspace. When HR disables a leaver's account, their WiFi access ends with it. You no longer rotate a shared password across every site. This covers joiners, movers and leavers from one directory, instead of a separate WiFi account list.

Is Purple compliant with GDPR?

Yes. Purple is CCPA/CPRA and GDPR compliant and certified to ISO 27001 and Cyber Essentials. Guest data capture uses conscious-choice opt-ins, so visitors decide what they share. Purple has operated since 2012 across 80,000+ live venues. That compliance posture applies to both guest WiFi data and staff authentication records held on the platform.

Key Definitions

RADIUS

Remote Authentication Dial In User Service, specified in IETF RFC 2865. It defines how a network access server, such as an access point or switch, sends an access request to a central server and receives an accept or reject decision, optionally with attributes such as a VLAN assignment.

Every option in this guide authenticates devices through RADIUS. The decision is whether you host it as a cloud service on its own or buy it bundled inside a NAC platform.

IEEE 802.1X

The IEEE standard for port-based network access control. It carries authentication between the device, the access point or switch, and the RADIUS server, and keeps a port or wireless association closed until the server approves the identity.

Portnox, Purple, SecureW2 and JumpCloud all use 802.1X. The question is whether you need it on wired switch ports as well as WiFi, which drives switch configuration effort at every site.

Network access control (NAC)

A platform that adds device discovery across wired, wireless and VPN connections, posture assessment against a security baseline, and quarantine or remediation of failing devices, on top of 802.1X and RADIUS authentication.

You meet NAC when an auditor or insurer asks for one access policy across wired, wireless and VPN. It earns its cost where posture and wired enforcement are genuine requirements.

Posture assessment

A check, usually performed by an endpoint agent, that a device meets your security baseline, such as patch level, antivirus status or disk encryption, before it is admitted to the network.

Posture is the main capability that separates NAC from cloud RADIUS. If you do not need it, you avoid deploying and maintaining an agent on every managed device.

VLAN

A virtual LAN, defined in IEEE 802.1Q, which splits one physical network into separate logical segments. A RADIUS server can return a VLAN assignment so each authenticated device lands on the correct segment.

VLANs isolate staff, guests, cash registers and other devices. Segmenting payment devices on their own VLAN is how many venues reduce PCI-DSS scope without NAC.

EAP-TLS

An Extensible Authentication Protocol method specified in IETF RFC 5216. The device and server authenticate each other with digital certificates inside a TLS handshake, removing passwords from WiFi authentication.

EAP-TLS is the core of SecureW2's certificate-first approach. Choose it when you run a managed fleet and want certificates on wired and wireless without full NAC.

PEAP

Protected EAP, an 802.1X authentication method that wraps a username and password exchange inside an encrypted TLS tunnel established with the server's certificate.

PEAP lets staff join WiFi with directory credentials instead of device certificates, which lowers onboarding effort where you have no PKI in place.

iPSK

Identity pre-shared key, a method that gives each person or device its own WiFi key on a single network name, with the RADIUS server mapping each key to an identity and VLAN.

Purple supports iPSK for staff WiFi without certificates. It replaces a shared password per site, so one employee departure no longer forces a password change across every venue.

MAC authentication bypass (MAB)

A fallback that admits devices unable to run an 802.1X supplicant, such as printers, by checking their hardware MAC address against an allowed list on the RADIUS server.

MAB matters when you extend wired 802.1X to fixed devices. It is listed as a Portnox staff method and as the fallback for cloud RADIUS on wired ports.

Captive portal

The web page a visitor sees before WiFi access is granted, used for terms acceptance, login and consent capture. HTTPS pages cannot be redirected cleanly to it, which can trigger certificate warnings in the browser.

Portnox, SecureW2 and JumpCloud do not run guest WiFi, so you would buy a captive portal separately. Purple includes it with conscious-choice opt-ins and first-party data capture.

PCI-DSS

The Payment Card Industry Data Security Standard, published by the PCI Security Standards Council. It treats network segmentation as a way to reduce the scope of the cardholder data environment.

Retail and hospitality estates often meet their wired requirement by isolating cash registers on dedicated VLANs. Confirm the segmentation design with your Qualified Security Assessor before relying on it.

NIST SP 800-207

The US National Institute of Standards and Technology special publication on zero trust architecture. It describes continuous assessment of devices and identities before and during access to resources.

Government networks handling sensitive data and clinical networks often cite zero trust guidance when they justify full NAC with posture checks everywhere.

Worked Examples

A regional council runs 12 office buildings and nine libraries, with 600 wired desk ports, 1,100 managed laptops and a VPN for home working. Its insurer wants evidence that unknown devices cannot reach the corporate network. What should it deploy?

The council deployed NAC across wired, wireless and VPN, with posture checks on managed laptops. Library visitor WiFi moved to a separate guest SSID on its own VLAN, outside NAC scope. Three separate access policies became one, and all 600 desk ports moved under enforcement. Visitor devices stayed out of the NAC license count entirely. This modeled scenario shows where NAC belongs: the wired and posture requirement is real, so the cost is justified, while visitor WiFi gains nothing from it.

A hotel group runs Cisco Meraki access points across 30 hotels with one shared staff password per hotel. A Portnox quote covers 4,500 endpoints, but only 1,800 staff devices actually join WiFi, plus guest access. How should it scope the purchase?

The group kept wired registers on a segmented VLAN managed at the switch. Staff WiFi moved to identity-based 802.1X against Microsoft Entra ID, and guest WiFi moved to a captive portal with opt-in consent on the same platform. The licensed scope fell from 4,500 endpoints to the 1,800 staff devices that join WiFi. Thirty shared passwords were retired, so a leaver no longer forces 30 password changes. Guest and staff access now run from one console instead of two products. This is a modeled scenario.

A retailer with 120 stores already uses JumpCloud as its directory and is evaluating Portnox for staff handhelds and phones on WiFi. Registers are wired on a separate network. Does it need NAC?

The team applied the three-question test. Wired registers were already segmented, posture checks were not required, and no auditor asked for a unified policy. Staff WiFi moved to 802.1X against the existing directory, and shopper WiFi ran separately with its own captive portal. The team avoided rolling a posture agent to 1,400 handhelds and phones and retired 120 shared store passwords. A leaver now loses WiFi access in every store when their directory account is disabled. This is a modeled scenario.

Frequently asked questions

Is Purple a direct replacement for Portnox?

No, not for every Portnox use case. Purple replaces Portnox where your requirement is WiFi authentication for staff and guests. Purple does not offer wired port enforcement or endpoint posture checks. If you need those, keep a NAC for the wired and managed-laptop estate. Run Purple for venue WiFi, where it also provides the captive portal, conscious-choice opt-ins and WiFi analytics that Portnox does not position itself to deliver.

Can I run cloud RADIUS for WiFi and keep a NAC for wired ports?

Yes, and many estates should. Scope the NAC to sites and devices that need posture checks, such as head office desks and managed laptops. Run venue and guest WiFi on a separate cloud RADIUS platform. This keeps guest devices out of your NAC license count. It also avoids deploying posture agents to cell phones and handhelds that never touch sensitive systems.

Does Purple work with the access points I already own?

Yes. Purple is hardware-agnostic and runs as a cloud overlay on Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. No rip and replace is required. You point your access points at Purple for authentication and the captive portal, and your existing wireless network keeps running underneath.

How do I migrate staff WiFi from Portnox to cloud RADIUS?

Migrate one SSID and one site at a time. Create the new staff network alongside the existing one, authenticated against Microsoft Entra ID, Okta or Google Workspace. Move a pilot group, confirm VLAN assignment and roaming, then expand. Leave wired enforcement on Portnox until you have decided whether wired posture is still a requirement. Retire the old SSID only once every device has moved.

Is cloud RADIUS without NAC enough for PCI DSS?

Yes, for many card-accepting venues, provided payment systems are segmented. PCI DSS treats network segmentation as a way to reduce the scope of cardholder data environments. Keep registers and payment devices on isolated wired VLANs. Run staff and guest WiFi on separate segments authenticated through cloud RADIUS. Confirm your segmentation design with your Qualified Security Assessor before you rely on it.

Is SecureW2 or JumpCloud cheaper than Portnox?

Usually yes for WiFi-only needs, because you avoid paying for unused NAC features. JumpCloud publishes per-person monthly packages with RADIUS in selected tiers. SecureW2 and Portnox quote per deal. Compare total cost, not license price. Include agent maintenance, certificate management, switch configuration and a separate guest WiFi platform, which all three require and Purple includes.

Does cloud RADIUS handle leavers automatically?

Yes, when it authenticates against your identity provider. Purple's Identity-Based Networks check staff against Microsoft Entra ID, Okta or Google Workspace. When HR disables a leaver's account, their WiFi access ends with it. You no longer rotate a shared password across every site. This covers joiners, movers and leavers from one directory, instead of a separate WiFi account list.

Is Purple compliant with GDPR?

Yes. Purple is CCPA/CPRA compliant and certified to ISO 27001 and Cyber Essentials. Guest data capture uses conscious-choice opt-ins, so visitors decide what they share. Purple has operated since 2012 across 80,000+ live venues. That compliance posture applies to both guest WiFi data and staff authentication records held on the platform.

Got questions about your specific setup?

Our team works with venue operators, IT managers, and network engineers across 80,000 venues. Book a 20-minute call and we will show you how others like you solved it.