Mandatory server-certificate validation
Clients must verify the RADIUS server's certificate before sending credentials. Closes the evil-twin attack that plagued mis-configured WPA2-Enterprise deployments.
Deploy WPA2-Enterprise or WPA3-Enterprise with 802.1X on your existing access points. Every user authenticates against your identity provider, every device gets a unique session key, and access can be revoked per-device in a single click. Purple operates the RADIUS and certificate infrastructure as a cloud service - you keep the hardware you already own.
Compare Cloud RADIUS against traditional on-premises Microsoft NPS or FreeRADIUS servers across your network infrastructure.
Architecture Insight: Cloud RADIUS eliminates Windows NPS servers, CA certificate renewals, and complex Active Directory domain joins across remote branch offices.
The WPA standard has two modes. WPA-Personal (WPA2-PSK, WPA3-SAE) uses a single password shared across everyone who joins the SSID. Good enough for a home. WPA-Enterprise authenticates each user or device individually via 802.1X against a RADIUS server. Required for any venue that cares about revocation, audit, or compliance.
| Security dimension | WPA-Personal (PSK / SAE) | WPA-Enterprise (802.1X) |
|---|---|---|
| Credential | Shared passphrase | Per-user certificate, password, or iPSK |
| Infrastructure | Just the access points | APs + RADIUS server (or RADIUS-as-a-Service) |
| Revocation | Rotate the network-wide passphrase | Disable one user in the IdP |
| Audit trail | None - all devices look identical | Per-user session logs |
| Right for | Homes, tiny single-trust venues | Offices, hotels, campuses, stadiums, anything regulated |
Eliminate complex on-premises NPS RADIUS hardware and server maintenance. Purple acts as a zero-trust cloud overlay on your existing network hardware.
Authorize Purple with your Microsoft Entra ID (Azure AD), Google Workspace, or Okta account via single sign-on (SSO) and SCIM. No local Active Directory agent or domain controller modifications required.
In your Meraki, Aruba, Ruckus, Mist, or UniFi dashboard, enter Purple’s redundant Cloud RADIUS IP addresses, authentication ports (1812/1813), and shared secret for your WPA2/WPA3-Enterprise SSID.
Select your preferred authentication protocol: EAP-TLS with automated PKI device certificates or PEAP-MSCHAPv2 with corporate directory credentials. Set fallback policy and VLAN assignments.
Deploy Passpoint (Hotspot 2.0) or automated WiFi profiles to employee laptops and mobile devices via MDM (Intune, Jamf, Kandji). When an employee leaves, access is automatically revoked in real time.
Looking to migrate from legacy Microsoft NPS or FreeRADIUS servers? Speak with our wireless architecture team
WPA3 is not just a bigger WPA2. Four changes matter for enterprise deployments.
Clients must verify the RADIUS server's certificate before sending credentials. Closes the evil-twin attack that plagued mis-configured WPA2-Enterprise deployments.
Deauthentication and disassociation frames are cryptographically signed, so attackers can no longer knock clients off the network with spoofed frames.
Optional high-security mode for government, defense, and critical infrastructure. Suite B cryptography throughout - key exchange, encryption, and MAC.
WPA3-Enterprise can run in transition mode on the same SSID as WPA2, so you do not need a hard cutover. Newer clients negotiate WPA3; older ones fall back to WPA2-Enterprise.
Compare WPA2-Enterprise against a shared PSK to see how the two modes differ on per-user credentials, audit logs, and employee offboarding.
Speak directly with our senior wireless engineers. We will analyze your access point infrastructure, identity provider setup, and compliance goals.
wpa-enterprise-quote)WPA-Enterprise is the IEEE 802.11 security mode designed for organizations. Instead of a single shared password (WPA-Personal), each user or device authenticates individually against a RADIUS server via 802.1X, typically with a certificate (EAP-TLS) or username and password (PEAP). Every session gets a unique encryption key, and access can be revoked per-device without disrupting the rest of the network.
WPA3-Enterprise fixes known weaknesses in WPA2-Enterprise. The most important changes: server-certificate validation is now mandatory (closes the evil-twin attack vector that plagued WPA2), management frames are protected, and the optional 192-bit Suite B mode offers defense-grade cryptography. WPA3-Enterprise is backwards-compatible with WPA2-Enterprise in a transition mode, so you can upgrade gradually.
Three parties are involved. The supplicant (client device) asks to join. The authenticator (access point) holds the client in a quarantine state and forwards its EAP messages to an authentication server (RADIUS). The RADIUS server validates the credential - certificate, password, or token - and tells the access point to admit or reject. Each successful session gets a unique encryption key derived from the authentication, so one compromised device cannot decrypt another.
EAP-TLS uses a TLS handshake with mutual certificate authentication. The client proves its identity with a device certificate, the server proves its identity with a server certificate, and the session key is negotiated inside the encrypted tunnel. There is no password to phish or steal - you would have to extract the private key from the device itself. For managed fleets with an MDM, EAP-TLS is the right default.
Most enterprise-grade access points released from 2020 onwards support WPA3-Enterprise in firmware. You typically enable WPA3-Enterprise on the SSID and keep WPA2 as a fallback during the transition. Older APs may only support WPA2-Enterprise - those are still secure when paired with cloud RADIUS and EAP-TLS, so a forklift upgrade is rarely needed.
Yes - WPA-Enterprise is defined around an external authentication server, which in practice means RADIUS. You can run it on-premise (FreeRADIUS, Microsoft NPS, Cisco ISE) or consume it as a service. Purple RADIUS-as-a-Service is the cloud-hosted option most customers pick when they do not want to operate servers.
Yes, when deployed correctly. The known attacks on WPA2-Enterprise all require either a mis-configured client (no server-certificate validation, which is what WPA3 makes mandatory) or physical access to a device. Enforcing server-certificate validation via MDM and using EAP-TLS closes the practical risks. WPA3-Enterprise is still preferred going forward, but there is no reason to panic-migrate a working WPA2-Enterprise deployment.
Two good options. First, iPSK (Identity PSK) gives each device a unique pre-shared key on a single SSID - the user experience of WPA-Personal, the per-device revocation of WPA-Enterprise. Second, MAC Authentication Bypass (MAB) admits known-good MAC addresses to a constrained VLAN. Purple supports both alongside WPA2/3-Enterprise on the same network.
Yes - you do not need to run your own RADIUS server. WPA2-Enterprise requires a RADIUS authentication server by definition, but with Purple RADIUS-as-a-Service that server is cloud-hosted: you point your access points at Purple instead of standing up FreeRADIUS, Microsoft NPS, or Cisco ISE. You still get full 802.1X with EAP-TLS or PEAP against Entra ID, Okta, or Google Workspace, with no on-premise authentication hardware to install, patch, or keep highly available.
WPA2-Enterprise uses 802.1X with CCMP-128 encryption. WPA3-Enterprise introduces mandatory Protected Management Frames (PMF) to prevent deauthentication attacks, supports 192-bit cryptographic suites (CNSA / Suite B), and eliminates obsolete fallback ciphers.
Yes. Purple Cloud RADIUS replaces legacy Microsoft NPS and FreeRADIUS servers. Your wireless access points authenticate directly via redundant cloud RADIUS endpoints integrated with Microsoft Entra ID, Okta, or Google Workspace.
Purple syncs with Entra ID using SCIM and OAuth 2.0. When an employee logs in via 802.1X or a client certificate, RADIUS checks user status and group membership in Entra ID in real time. Disabling an account in Entra ID revokes WiFi access immediately.
Last reviewed:
See how WPA-Enterprise works in venues like yours, and how Purple compares to alternatives.
Purple layers WPA2/3-Enterprise, cloud RADIUS, and managed certificates on top of Cisco, Aruba, Ruckus, Juniper Mist, Meraki, or Ubiquiti. Live in days.