Skip to main content

What is MAC randomisation?

Definition

MAC randomisation, also spelt MAC randomization, is a privacy feature in iOS 14 and later, Android 10 and later, and Windows that makes a device use a randomly generated MAC address instead of its hardware one. It stops tracking across networks, but it breaks systems that identify devices by MAC address.

MAC randomisation explained

Devices apply randomisation in two ways. Some keep a stable random address per network, so the same phone looks consistent on one SSID but different on another. Others rotate the address periodically, even on the same network. Either way, the address a venue sees is no longer the device’s burned-in hardware address.

The effects show up in familiar places. Returning guests are asked to sign in to the captive portal again because the network no longer recognises them. Analytics platforms report more unique visitors than there really are. DHCP scopes can run out faster in busy venues, and network access control rules keyed to MAC addresses stop matching.

The durable fix is to identify people and devices by something other than the MAC address. Passpoint and OpenRoaming carry a credential, social login and email sign-in identify the person, and 802.1X with EAP-TLS identifies the device by its certificate. For managed fleets, MDM profiles can disable private addresses on corporate SSIDs where a fixed identifier is needed.

Need more than a definition?

Talk to our team about how Purple combines guest WiFi, captive portals, RADIUS, and analytics into a single platform that runs on the access points you already own.