Skip to main content

Bulk internet agreement vs managed WiFi: which model fits your building

A practical procurement reference for property, IT and operations leaders comparing resident-paid retail broadband, a bulk internet agreement and managed WiFi. It clarifies ownership, resident move-in, security, cost scope and contractual exit, using US bulk-internet framing and UK equivalents.

By Marketing TeamPublished Updated
📖 3 min read762 words3 worked examples10 key definitions

Video overview

Listen to this guide

View podcast transcript
Welcome to Purple's technical briefing on bulk internet agreements versus managed WiFi. If you own or operate a building, connectivity is no longer just a line item on a utility schedule. It affects move-in readiness, support demand, building access, security boundaries, and your ability to change providers later. The first point is straightforward. There are three common ways to provide residential or venue connectivity. You can let each resident buy their own retail broadband. You can buy a building-wide connection from one ISP, usually called bulk internet in the United States. Or you can run managed WiFi as a building service, where the building or its appointed operator manages the access network and the resident experience. These are not interchangeable procurement labels. They assign responsibility differently. Under resident-paid retail broadband, every resident becomes a separate buyer. They choose, order, install, pay for, and cancel their own service. That can preserve individual choice where several providers can reach the property. But it also means your move-in team inherits a different failure pattern. A resident who arrives on Friday with no active service will be calling a retail provider, not your network team. You may have little visibility of the in-building equipment, and little ability to standardize coverage or isolate faults. A bulk internet agreement changes the commercial model. The building owner or operator contracts with a single ISP to supply service for the property. The cost is commonly recovered through rent, a service charge, or a separate resident fee. In US multi-family environments, the FCC says bulk billing itself is not currently prohibited. It also says service providers may not use a bulk billing agreement that gives them exclusive rights to access and serve the building. That distinction matters. A building-wide contract can be lawful while a contract that blocks all competing provider access can create a problem. In the UK, you are more likely to hear building-wide broadband, landlord-provided internet, or a block broadband agreement. The procurement principle is the same. You need to separate the upstream connection from the inside-building network. The government requires new homes in England to have gigabit-capable infrastructure and, where available within the defined cost cap, a gigabit-capable connection. For existing blocks, the Telecommunications Infrastructure Leasehold Property Act created a route for operators to seek access when a landlord is repeatedly unresponsive. Neither point tells you which commercial model to buy. Both make access, ducts, risers, and termination points part of the decision. Managed WiFi takes a different position. It treats in-building connectivity as an operating service rather than a retail product attached to each apartment. You decide who holds the upstream circuit contract, who owns or leases access points and switches, who provides monitoring, and how identities receive access. A managed service can run on the equipment you already own, but only if the design and contract say so. Purple is hardware-agnostic and integrates with Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. That gives you a route to keep the network asset separate from the ISP relationship. Now move from labels to the operating questions that matter. First, who owns the asset? In resident-paid broadband, the retail provider normally controls the service endpoint and may provide a router within each unit. Your property is still responsible for shared paths, access permissions, and any landlord-owned wiring. In bulk internet, the ISP may own the circuit and some of the active equipment. You must identify what happens to that equipment at contract end. In managed WiFi, the building can own the access layer or lease it under a service agreement. The better model is not the one with the lowest headline connection price. It is the one that makes ownership, replacement, and handover explicit. Second, what happens at move-in? With retail broadband, the resident places an order and waits for the provider to activate service. With bulk internet, a connection may already exist, but the resident still needs the supplier's onboarding and support process. With managed WiFi, the design can make access available from the first day, then apply an identity policy to the resident. That policy might use a WiFi Pass, iPSK, or a private network bubble, depending on your design. Do not buy the term without testing the handover. Third, what happens when a resident leaves? Retail broadband ends or transfers under the resident's account. With bulk internet, billing and access removal depend on the service agreement. With managed WiFi, your joiners, movers, leavers process should remove access at the end of occupancy and retain only the records your data policy requires. This is where centrally managed Identity-Based Networks are useful. They tie network access to a role or identity, rather than leaving a static shared credential behind. The next question is cost. Is bulk internet cheaper than managed WiFi? Often, it looks cheaper at the circuit level because one building-wide commitment can replace many retail tariffs. But that comparison is incomplete. Include the access layer, survey, installation, power, monitoring, support, replacement cycles, resident communications, service credits, data handling, and exit costs. Compare total operating cost over the contract term, not the first monthly price. A low wholesale rate is not a low-cost service if your team then handles every coverage fault, apartment move, and equipment swap. A practical tender asks bidders to price the same scope. It should cover the upstream circuit, in-building cabling, access points, switches, authentication, management, fault handling, resident support, data protection, and end-of-term handover. Ask for one-time costs, recurring charges, implementation milestones, response times, service credits, and the ownership of every component. A bidder that cannot identify the demarcation point has not priced the same service. Then test security. Resident convenience is not a reason to create a flat network. IEEE 802.1X is the standard for port-based network access control. It uses a controlled port for secure access-controlled communication and an uncontrolled port for authentication and key management. For staff devices, payment systems, building operations, and resident access, use segmentation that reflects risk. The PCI Security Standards Council publishes separate guidance on scoping and segmentation for modern architectures. That is relevant wherever a hotel, retailer, stadium, or conference venue has cardholder data systems. Put resident and guest traffic outside the payment environment, define permitted paths, and test the boundaries after changes. For staff networks, enterprise authentication gives you a cleaner answer than one shared password. Use IEEE 802.1X with an appropriate Extensible Authentication Protocol and a RADIUS service. For supported equipment, assess WPA3-Enterprise as part of the security design. Define device compatibility before you mandate it. For residents, a private network bubble or individual pre-shared key can preserve separation between households without turning move-in into an IT project. The important control is not the label. It is the ability to issue, change, and revoke access without affecting every other resident. Do not confuse a captive portal with the whole security design. A captive portal is the splash page shown before an internet connection is granted. It manages login and can present terms or an opt-in choice. Purple recommends an open WiFi network for WiFi services when you want to reduce friction. Device operating systems generally use a Captive Network Assistant to recognize that internet access needs a login. The controller manages the interaction with the splash-page service, then passes the one-time login to RADIUS to complete access. That process can support a move-in experience. It does not replace segmentation, identity management, or a documented support model. Privacy needs a line in the requirements as well. If the WiFi journey collects information that identifies a resident, guest, or visitor, then your purpose, collection fields, retention, and responsibilities matter. The FTC and state attorneys general say that CCPA/CPRA principles include purpose limitation, data minimization, storage limitation, integrity and confidentiality, and accountability. Write down whether the building, the operator, or both decide the purpose and means of processing. Use conscious-choice opt-ins. Do not collect demographic or marketing information by default merely because the login journey can ask for it. Here are two short real-world examples. In retail, Harrods used Purple Guest WiFi and a captive portal to support its Harrods Rewards program. Purple reports that 581,317 unique individuals logged on over 12 months, 38% opted in to marketing communications, and 4,453 people signed up to Harrods Rewards after expressing interest in the login process. The procurement point is not that every building should copy a retail login flow. It is that the access layer, identity journey, consent, and business process must be designed together. At the Formula 1 Mexico City Grand Prix, Purple and partner Telmex used branded WiFi journeys at a mass sporting event. Purple reports 38,200 fan journeys, an 86% authentication rate, 6,700 new leads, and 18,000 redirections to the Telmex website. Again, this is a different operating environment from a Multi-Family building. The transferable lesson is capacity planning with a defined access journey. Choose where an identity step adds value and where it creates delay. For your estate, select bulk internet when you want a single commercial relationship for service delivery and are content for the provider to operate most of the stack. Select resident-paid broadband when choice and separate consumer contracts matter more than a standardized move-in experience. Select managed WiFi when you need building-level control over access, segmentation, lifecycle operations, and the asset. In practice, hybrid designs are common. You might buy one building-wide circuit, own the structured cabling, and appoint a managed service to run WiFi while retaining the right to change the ISP. Before approval, run one final workshop. Bring property, IT, legal, security, finance, and operations together. Mark the fiber handoff, risers, switches, access points, cloud services, support desk, data roles, and billing owner on one diagram. Then simulate a Friday move-in, a lost device, an ISP fault, a resident leaving, an access-point failure, and lease expiration. If the owner and action are clear in each scenario, the model is probably workable. If they are not, do not sign yet. Rapid-fire answers. Can you move from resident-paid broadband to managed WiFi? Yes, but survey the physical network, confirm access rights, decide equipment ownership, design resident communications, and run a phased cutover. Is bulk internet always cheaper? No. Compare the full operating scope and exit exposure. Who owns the network? Only the contract tells you. Make it explicit. What makes a strong managed WiFi design? Separate identities, isolated traffic, documented lifecycle controls, monitored infrastructure, and a tested handover plan. The decision is not about choosing a label. The decision is not about choosing a label. It is about assigning ownership, operation, security, and resident experience to the party that can run each part well. Make that accountability visible before you sign. Thank you for listening.

Part of our core series: Multi-Tenant WiFi Guide

Bulk internet agreement vs managed WiFi: which model fits your building

When selecting how a multi-family or Multi-Family (MDU) property delivers internet access, property operators face three distinct procurement models: a bulk internet agreement with a single ISP, individual resident-paid retail broadband, or property-wide managed WiFi delivered as a core building amenity.

Choosing the right approach dictates infrastructure capital expenditure, ongoing operational costs, resident move-in satisfaction, and long-term net operating income (NOI). This technical guide breaks down the procurement trade-offs, network asset ownership, day-one connection workflows, and churn management across all three connectivity models.

The Three Multi-Tenant Connectivity Models Explained

Property managers and developers generally evaluate three structural models for residential connectivity:

Feature / Metric Individual Retail Broadband Bulk Internet Agreement Property-Wide Managed WiFi
Procurement Relationship Resident contracts directly with retail ISP Property owner contracts bandwidth in bulk with ISP Property owner contracts commercial transit and managed network
Asset Ownership ISP owns wiring/ONT; resident leases router ISP owns distribution; building may own cabling Property owner owns enterprise cabling, switches, and access points
Move-In Experience 3 to 14 days waiting for router delivery or technician Immediate wired access; resident supplies own router Instant activation via captive portal or pre-provisioned Passpoint/iPSK
Revenue Opportunity Zero (ISP captures 100% of revenue) Marginal markup (amenity fee minus bulk cost) Significant recurring revenue via bundled technology amenity fees
Network Visibility & Control Zero property visibility; unmanaged RF interference Minimal visibility; unmanaged RF interference in units Complete centralized control; enterprise RF management and SLA guarantees

1. Individual Resident-Paid Broadband

In the traditional retail model, the property developer provides telecom conduit or fiber risers, but takes no active part in connectivity. Each resident contacts an ISP (e.g. Comcast, Spectrum, AT&T), orders a package, waits for delivery or technician dispatch, and installs a consumer wireless router.

The operational drawback: Units end up packed with dozens of consumer routers operating on overlapping 2.4 GHz and 5 GHz channels. Co-channel interference spikes, performance degrades across walls, and property management has no control over connectivity issues that negatively impact tenant satisfaction.

2. Bulk Internet Agreements

Under a bulk internet contract, the property owner signs an exclusive commercial agreement with a single internet service provider to supply all units at a discounted wholesale rate. The property charges residents a fixed technology fee as part of their monthly rent or amenity billing.

The trade-off: While bulk agreements deliver volume pricing, they often bind the property to 5-to-10 year exclusive contracts. Furthermore, most bulk agreements terminate at a wall jack or ONT in each apartment, still requiring residents to manage separate modems or access points rather than enabling seamless roaming across the entire building, amenities, gym, and courtyard.

3. Property-Wide Managed WiFi

In a modern managed WiFi deployment, enterprise access points (APs) are installed throughout residential units and shared communal areas (lounges, coworking spaces, pools, rooftop terraces). Bandwidth is delivered via redundant commercial leased lines, and traffic is segmented using Dynamic Pre-Shared Keys (DPSK / iPSK) or 802.1X enterprise authentication.

Residents experience instant, seamless connectivity from the moment of move-in. Each resident receives a secure Private Area Network (PAN) that follows them throughout the entire estate, allowing wireless printing, casting, and streaming without exposing devices to other tenants.

Day-One Move-In and Tenant Churn Workflows

Resident turnover is an operational friction point in Multi-Family housing. The connectivity model dictates the labor required during onboarding and departures:

  • Move-In Activation: With managed WiFi integrated into property management software (PMS) like Yardi, RealPage, or Entrata, tenant lease creation automatically provisions a unique DPSK passphrase or Passpoint profile. When the resident arrives on site, their cell phone connects immediately without waiting for hardware installation.
  • Tenant Churn & Security: When a lease ends, the PMS webhook automatically revokes the tenant DPSK. Their devices are immediately disconnected from the network, eliminating security risks and preventing former residents from consuming building bandwidth.

Frequently Asked Questions

Is bulk internet cheaper than managed WiFi for property owners?

Bulk internet often requires lower initial hardware investment because the ISP may subsidize unit cabling. However, property-wide managed WiFi generates higher recurring returns and adds property asset value by establishing building-owned enterprise network infrastructure.

How do managed WiFi networks keep resident devices private?

Enterprise multi-tenant networks employ client isolation and private VLANs (or Micro-segmentation). Even though multiple residents connect to a shared building SSID, each apartment unit operates inside an isolated Personal Area Network (PAN), preventing neighbors from viewing or accessing each other's devices.

Can residents connect smart home and headless IoT devices to managed WiFi?

Yes. Modern managed WiFi platforms provide a self-service resident onboarding portal where residents can register MAC addresses for game consoles, smart TVs, and IoT appliances that do not support web browsers or 802.1X certificates.

Key Definitions

Bulk internet agreement

A building-wide commercial arrangement where one ISP supplies service for all tenants or residents, with costs recovered through the building or provider billing process.

Use this term in US MDU procurement. Confirm it does not include prohibited exclusive provider access.

Resident-paid retail broadband

A model where each resident separately buys, activates and cancels broadband from a retail provider.

It prioritizes individual choice but can create inconsistent move-in and support experiences.

Managed WiFi

A building service in which the access network, resident access journey and operational support are centrally managed under a defined service model.

It fits properties where connectivity is part of the operating promise and lifecycle control matters.

Demarcation point

The documented boundary at which responsibility moves from one party or network component to another.

Put it in the contract and architecture diagram to avoid fault and cost disputes.

IEEE 802.1X

The IEEE standard for port-based network access control, using EAP to authenticate access before a controlled port permits normal communication.

Use it for staff and managed-device access where individual identity matters.

RADIUS

A service used to authenticate and authorize network access requests and return the policy associated with an identity.

It sits behind identity-based access workflows, including controlled WiFi onboarding.

Captive portal

The splash page shown before internet access is granted on a WiFi service.

Use it for login, terms and opt-ins, not as the sole network security control.

iPSK

An individual pre-shared key assigned to a person or device rather than shared across a whole building.

It can help isolate households and make access revocation more precise.

Private network bubble

A policy pattern that groups authorized household devices into a private area while separating them from other residents.

Consider it when residents expect personal-device discovery without cross-household exposure.

Joiners, movers, leavers

The operating process used to grant, change and remove access as a person’s relationship with the building changes.

It is the key lifecycle test for a managed building service.

Worked Examples

A 220-unit Multi-Family building wants connectivity available when residents collect keys, but currently allows individual retail broadband orders.

Survey risers, closets and unit coverage first. Establish who owns usable cabling and active equipment. Run a managed WiFi pilot on a representative section, define the resident identity and support journey, then phase the cutover with parallel retail service where permitted. Approve only after coverage, capacity, security boundaries and service-desk handover pass acceptance testing.

A 90-room hotel is offered a low-cost bulk internet agreement bundled with on-site equipment and support.

Price the same scope against a retained-access-layer option. Require the ISP to list circuit, switches, access points, cabling, cloud management, response targets and service credits separately. Confirm the exit treatment of equipment and inside wiring, then run a fault drill that tests a guest outage, payment-environment segmentation and a failed access point.

A conference venue wants one service for exhibitors, staff, guests and temporary event networks.

Keep each role as a separate identity and traffic policy. Use 802.1X for managed staff devices, define guest access through the captive portal where appropriate, and isolate payment and operational systems. Test the design with peak-event capacity, exhibitor move-in, lost-device revocation and service-provider failure before the first contracted event.

Got questions about your specific setup?

Our team works with venue operators, IT managers, and network engineers across 80,000 venues. Book a 20-minute call and we will show you how others like you solved it.