Skip to main content

Technical Guides

Deep, expert-led technical guides on guest WiFi, analytics, captive portals, and venue technology.

Ready to move from research to rollout? See how Purple's captive portal software handles branded guest sign-in, analytics, and compliance in one platform.

341 guides

Connecting WiFi Events to 1,500+ Apps with Zapier and Purple
Automation

Connecting WiFi Events to 1,500+ Apps with Zapier and Purple

This guide details the technical architecture and practical implementation of integrating Purple WiFi with Zapier. It provides venue operators and IT teams with actionable recipes to automate CRM synchronisation, guest communications, and operational alerts without writing custom code.

4 mins read1k words
Age Verification on Guest WiFi: Compliance for Gaming, Alcohol, and Adult Venues
Captive Portals

Age Verification on Guest WiFi: Compliance for Gaming, Alcohol, and Adult Venues

This authoritative technical reference guide explores the implementation of age verification on guest WiFi networks for high-risk venues like casinos, bars, and stadiums. It details compliance strategies, architectural deployment models, and the balance between regulatory requirements and user onboarding friction.

4 mins read1k words
WiFi 7 MLO Explained: Multi-Link Operation for Seamless Roaming
WiFi Standards

WiFi 7 MLO Explained: Multi-Link Operation for Seamless Roaming

This technical reference guide provides a comprehensive deep-dive into WiFi 7 Multi-Link Operation (MLO) for enterprise network architects and IT leaders. It demystifies the three MLO operating modes (eMLSR, NSTR, and STR), explains how MLO supersedes legacy band steering, and delivers actionable deployment guidance backed by real-world trial data from the Wireless Broadband Alliance. Venue operators in hospitality, retail, and large public spaces will find concrete implementation strategies and ROI evidence to support WiFi 7 investment decisions.

9 mins read2k words
Rogue AP Detection: Protecting Venue WiFi from Impersonation Attacks
Security

Rogue AP Detection: Protecting Venue WiFi from Impersonation Attacks

This guide provides a comprehensive technical reference for IT managers, network architects, and venue operations directors on deploying Wireless Intrusion Prevention Systems (WIPS) to detect and neutralise rogue access points and evil twin attacks. It covers detection methodologies, legal countermeasures, compliance requirements, and real-world implementation scenarios across hospitality, retail, and public-sector environments. Organisations that implement the strategies outlined here will strengthen their wireless security posture, reduce compliance risk, and protect both their infrastructure and their users from WiFi impersonation threats.

9 mins read2k words
Microsoft Dynamics 365 and Guest WiFi Data Enrichment
Integrations

Microsoft Dynamics 365 and Guest WiFi Data Enrichment

This technical reference guide details the architecture, data modeling, and field mapping required to integrate guest WiFi data with Microsoft Dynamics 365. It provides actionable implementation strategies for IT managers and network architects to enrich unified customer profiles and drive measurable ROI in physical venues.

6 mins read1k words
ISO 27001 Guest WiFi: A Compliance Primer
Security

ISO 27001 Guest WiFi: A Compliance Primer

This authoritative technical reference maps guest WiFi deployments directly to ISO 27001:2022 controls, detailing network segregation, logging, and risk treatment requirements. It provides actionable guidance for IT managers and network architects on generating audit-ready evidence and leveraging vendor SOC 2 attestations to satisfy ISMS supplier assurance mandates.

5 mins read1k words
DNS Filtering for Guest WiFi: Blocking Malware and Inappropriate Content
Security

DNS Filtering for Guest WiFi: Blocking Malware and Inappropriate Content

This guide provides IT managers, network architects, and venue operations directors with a definitive technical reference for deploying DNS filtering on guest WiFi networks. It covers the architecture of DNS-level threat blocking, a vendor comparison of leading cloud DNS services, step-by-step implementation guidance, and real-world case studies from hospitality and retail environments. DNS filtering is the most cost-effective first line of defence against malware, phishing, and inappropriate content on public-facing networks, and this guide equips teams to deploy it confidently and in compliance with PCI DSS, GDPR, and HIPAA requirements.

11 mins read3k words
PoE Budget Planning for Multi-Site WiFi Deployments
Hardware

PoE Budget Planning for Multi-Site WiFi Deployments

This guide provides a practical framework for calculating Power over Ethernet (PoE) budgets across multi-site WiFi deployments. It covers the transition to PoE++ for WiFi 6E and 7, switch sizing strategies, and methods to future-proof infrastructure while mitigating the risks of power oversubscription.

5 mins read1k words
Guest WiFi Session Timeouts: Balancing UX and Security
Security

Guest WiFi Session Timeouts: Balancing UX and Security

This guide provides a practical framework for configuring guest WiFi session timeouts, balancing seamless user experience with robust security. It covers idle timeouts, absolute timeouts, re-authentication strategies, and industry-specific deployment scenarios for IT and venue operations leaders.

5 mins read1k words
RADIUS Server High Availability: Active-Active vs Active-Passive
Authentication

RADIUS Server High Availability: Active-Active vs Active-Passive

A definitive technical reference guide for IT managers and network architects evaluating RADIUS high availability architectures. It contrasts Active-Active and Active-Passive deployments, details database replication requirements, and explains how Cloud RADIUS mitigates failover latency for enterprise venues.

6 mins read1k words
OFDMA Explained: How WiFi 6 Handles Dense Environments
WiFi Standards

OFDMA Explained: How WiFi 6 Handles Dense Environments

Master WiFi 6 OFDMA, Resource Units (RUs), and subcarrier spacing. Learn how 802.11ax eliminates contention latency and optimizes high-density venue capacity.

6 mins read1k words
Network Onboarding UX: Designing a Frictionless WiFi Setup Experience
Captive Portals

Network Onboarding UX: Designing a Frictionless WiFi Setup Experience

This guide provides a comprehensive technical framework for designing a frictionless WiFi network onboarding UX, covering captive portal detection mechanics across iOS, Android, Windows, and macOS, and detailing self-service certificate enrolment for 802.1X staff networks. It equips IT managers, network architects, and venue operations directors with actionable strategies to reduce helpdesk overhead, improve first-connection success rates, and maintain GDPR and PCI DSS compliance across hospitality, retail, and campus environments.

9 mins read2k words
Azure AD and Entra ID WiFi Authentication: Integration and Configuration Guide
Integrations

Azure AD and Entra ID WiFi Authentication: Integration and Configuration Guide

This technical reference guide provides IT managers, network architects, and venue operations directors with a practical roadmap for integrating Microsoft Entra ID (Azure AD) with enterprise WiFi networks using RADIUS and 802.1X. It covers the architectural decision between on-premise Windows NPS and cloud-native RADIUS, the deployment of certificate-based EAP-TLS authentication via Microsoft Intune, and the operational best practices for securing wireless access across hospitality, retail, and public-sector environments. For organisations already invested in the Microsoft 365 and Entra ID ecosystem, this guide bridges the gap between cloud identity management and physical network security.

9 mins read2k words
Passwordless WiFi Authentication: Moving Beyond Pre-Shared Keys
Authentication

Passwordless WiFi Authentication: Moving Beyond Pre-Shared Keys

This guide provides IT managers, network architects, and venue operations directors with a practical roadmap for eliminating shared WiFi passwords and migrating to identity-based, certificate-driven authentication. It covers the security and compliance failures of PSK-based networks, the technical architecture of 802.1X and EAP-TLS, and the role of Identity PSK (iPSK) as a critical transition technology for IoT and legacy devices. Venue operators in hospitality, retail, and the public sector will find actionable migration strategies, real-world implementation scenarios, and measurable business outcomes to justify the investment.

10 mins read2k words
IoT Device Segmentation on WiFi: Isolating Non-Standard Devices
Network Design

IoT Device Segmentation on WiFi: Isolating Non-Standard Devices

This guide provides practical, enterprise-grade strategies for securely segmenting non-standard IoT devices on venue WiFi networks. Learn how to implement VLAN isolation, MAC-based authentication, and strict firewall policies to protect your core infrastructure from vulnerable smart devices.

5 mins read1k words
Cloud RADIUS vs on-premise RADIUS: decision guide for IT teams
Authentication

Cloud RADIUS vs on-premise RADIUS: decision guide for IT teams

Compare Cloud RADIUS and on-premise RADIUS (FreeRADIUS, NPS) for enterprise 802.1X WiFi security. Architectural comparison, TCO analysis, SCEP EAP-TLS integration, and WAN resilience.

10 mins read2k words
BYOD WiFi Onboarding: Managing Unmanaged Devices in Hotels and Retail
Authentication

BYOD WiFi Onboarding: Managing Unmanaged Devices in Hotels and Retail

This technical reference guide provides actionable strategies for onboarding employee-owned (BYOD) devices onto enterprise WiFi networks in hospitality and retail environments without requiring full MDM enrolment. It covers self-service certificate enrolment flows, 802.1X authentication, and policy enforcement to ensure secure access for unmanaged devices.

6 mins read1k words
Okta and RADIUS: Extending Your Identity Provider to WiFi Authentication
Integrations

Okta and RADIUS: Extending Your Identity Provider to WiFi Authentication

This guide provides a comprehensive technical reference for IT administrators at Okta-centric organisations who want to extend their cloud identity provider to WiFi authentication using the Okta RADIUS agent. It covers the full authentication architecture, MFA enforcement trade-offs, dynamic VLAN assignment via RADIUS attribute mapping, and the critical decision between password-based EAP-TTLS and certificate-based EAP-TLS. Venue operators and enterprise IT teams will find actionable deployment guidance, real-world case studies from hospitality and retail, and a clear framework for integrating Okta RADIUS alongside dedicated guest WiFi solutions.

11 mins read3k words
PEAP-MSCHAPv2: Why It Is Still Common, Why It Is Risky, and How to Move On
Security

PEAP-MSCHAPv2: Why It Is Still Common, Why It Is Risky, and How to Move On

A comprehensive technical reference guide detailing the critical security vulnerabilities of PEAP-MSCHAPv2, including evil twin attacks and credential capture. It provides a practical, vendor-neutral roadmap for IT teams to migrate enterprise WiFi networks to secure, certificate-based EAP-TLS authentication.

5 mins read1k words
Zero Trust WiFi Architecture: Applying Zero Trust to Venue Networks
Security

Zero Trust WiFi Architecture: Applying Zero Trust to Venue Networks

A comprehensive technical reference guide detailing how venue operators can apply Zero Trust principles to enterprise WiFi networks. It covers continuous verification, micro-segmentation, and device posture enforcement to secure hospitality, retail, and public-sector environments against lateral movement and compliance risks.

8 mins read2k words
EAP Methods Compared (PEAP, EAP-TLS, EAP-TTLS, EAP-FAST): Enterprise 802.1X Guide
Authentication

EAP Methods Compared (PEAP, EAP-TLS, EAP-TTLS, EAP-FAST): Enterprise 802.1X Guide

Compare enterprise 802.1X EAP authentication protocols: security levels, client certificate requirements, PKI complexity, and RADIUS integration for WPA3-Enterprise.

6 mins read1k words
Microsoft Intune WiFi Certificate Deployment via SCEP and PKCS
Integrations

Microsoft Intune WiFi Certificate Deployment via SCEP and PKCS

This guide provides a step-by-step technical reference for deploying WiFi authentication certificates via Microsoft Intune using SCEP and PKCS. It is designed for IT managers and network architects implementing passwordless 802.1X WiFi to ensure seamless, secure connectivity across enterprise environments.

6 mins read1k words
Jamf and RADIUS: Certificate-Based WiFi Authentication for Apple Device Fleets
Integrations

Jamf and RADIUS: Certificate-Based WiFi Authentication for Apple Device Fleets

This technical reference guide provides IT managers, network architects, and CTOs with actionable steps to deploy certificate-based 802.1X WiFi authentication for Apple device fleets using Jamf Pro and RADIUS. It covers the full SCEP certificate provisioning workflow, WiFi configuration profile structure, RADIUS integration requirements, and real-world implementation scenarios from healthcare and enterprise environments. The guide is essential for any organisation seeking to eliminate password-based WiFi vulnerabilities, reduce helpdesk overhead, and achieve compliance with PCI DSS and GDPR network access standards.

9 mins read2k words
PKI Fundamentals for WiFi Administrators: Certificates, CAs, and Trust Chains
Security

PKI Fundamentals for WiFi Administrators: Certificates, CAs, and Trust Chains

This technical reference guide explains the foundational concepts of Public Key Infrastructure (PKI) for enterprise WiFi administrators, covering certificate authorities, trust chains, and X.509 certificates. It details how PKI underpins EAP-TLS mutual authentication and provides actionable deployment guidance for IT teams in hospitality, retail, and public-sector environments. Understanding PKI is a mandatory prerequisite for deploying certificate-based staff WiFi authentication with Purple.

8 mins read2k words