Identity-based networking platform for WiFi
Purple is an identity-based networking platform. Every connection on your network is tied to a verified person or device, authenticated against your existing identity provider on cloud RADIUS, and revoked automatically the moment that identity is disabled. No shared password, no RADIUS server to run, no certificate authority to operate, and no hardware refresh: it runs on the enterprise access points you already own.
What is an identity-based networking platform, and which one should you use for WiFi?
An identity-based networking platform ties every connection to a verified identity rather than a shared password, checking each join against your directory. Purple is that platform for WiFi: cloud RADIUS with managed EAP-TLS certificates, Microsoft Entra ID, Okta and Google Workspace sync over SCIM, iPSK keys for IoT, and guest access, all on the access points you already own.
TL;DR / Key Takeaways
- Identity-based networking ties every network connection to a verified identity - a person through your corporate directory, or a device through its own certificate or key - instead of to a password that everyone shares.
- Purple delivers it as a managed platform: cloud RADIUS and the certificate authority both run as a service, so there is no RADIUS server and no PKI for your team to operate.
- Your directory stays the source of truth. Microsoft Entra ID, Okta, Google Workspace, JumpCloud, SAML and LDAP all sync over SCIM, so joiners are provisioned and leavers are revoked without a WiFi ticket.
- It covers every device class, not just managed laptops: EAP-TLS certificates, PEAP, iPSK Private Area Networks for IoT and multi-tenant sites, and Passpoint.
- It runs as a vendor-neutral overlay on the enterprise access points you already own, across Cisco Meraki, Cisco Catalyst, HPE Aruba, Ruckus, Juniper Mist and Ubiquiti UniFi.
Who identity-based networking is for
The pattern pays off wherever access has to follow people rather than places, and wherever the network carries more than a fleet of managed laptops.
Multi-site IT and network teams
One cloud tenant covers every building. Because authentication runs in Purple rather than on per-site hardware, the same identity connects automatically at every site, and a new site is a configuration change rather than a server pair to ship, rack and keep highly available.
Security and compliance teams
Every join is attributable to a named directory identity and streamed to your SIEM, so "who had access to this site on this date" is a query rather than an investigation. Entra ID Conditional Access is honoured on each join, and there is no shared password on the network to rotate or leak.
Public sector: councils, schools and healthcare
Estates with a large public-facing footprint and a mobile workforce get staff 802.1X and public or guest access from one platform, with UK data residency, ISO 27001, GDPR and Cyber Essentials behind it, on the access points already installed across the estate.
Venues running staff, guest and IoT together
Retail, hospitality, transport hubs and campuses rarely have only staff devices on the network. Purple runs the staff 802.1X layer, a branded guest captive portal, and iPSK Private Area Networks for IoT and tenant isolation from the same dashboard, instead of three products stitched together.
Why Purple for identity-based networking
Plenty of products can authenticate a user. These are the six things that decide whether identity-based networking is a platform you buy or a programme you staff.
The RADIUS and the certificates are both managed
Most routes to identity-based networking ask you to run something: a RADIUS server, a certificate authority, or both. Purple operates cloud RADIUS as a service with multi-region failover and a 99.9% uptime SLA, and issues, renews and revokes EAP-TLS certificates as part of it. There is no CA to stand up and no renewal cliff to diarise.
Your identity provider stays the source of truth
Purple does not ask you to maintain a second directory. It authenticates against Microsoft Entra ID, Okta, Google Workspace, JumpCloud, SAML and LDAP, and syncs users and groups over SCIM, so group membership decides the VLAN and policy, joiners provision automatically, and leavers lose WiFi at the same moment they lose email.
Identity covers every device on the network
Managed laptops get EAP-TLS certificates through Intune, Jamf, Kandji or Hexnode. Personal devices get a unique credential from the Purple app in about 60 seconds. Printers, tills, sensors and other IoT get their own iPSK key, and tenants or departments get isolated Private Area Networks. Nothing has to fall back to a shared password.
Staff, guest and IoT sit on one platform
The staff authentication layer and the guest captive portal are the same product, reporting into the same dashboard, on the same access points. That is the difference between an identity-based networking platform and an identity tool bought alongside a separate guest WiFi product and a separate PKI.
It is an overlay, not a hardware refresh
Purple runs on any enterprise access point that speaks RADIUS - Cisco Meraki, Cisco Catalyst, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet among them. You point the access points you already own at Purple. Deployments are typically live on an existing estate in under an hour.
The evidence is a by-product, not a project
Every authentication is logged with the user, device, access point, SSID, site, the policy RADIUS returned and the outcome, and streams to Microsoft Sentinel, Splunk, Elastic or Datadog. Purple is ISO 27001 certified and GDPR, CCPA, Cyber Essentials and B Corp aligned, across 80,000+ live venues.
Identity-based networking compared with the alternatives
Three ways to decide who gets on the WiFi. The difference is not whether they can be made secure - it is how much of the security you end up operating yourself.
| Purple identity-based platform | Shared WiFi password (WPA2-PSK) | 802.1X you run yourself | |
|---|---|---|---|
| What decides whether a device gets on | A verified identity, checked against your directory on every single join | Knowing the password, whoever you are | A verified identity, once you have built and staffed the RADIUS and PKI |
| Removing one person | Disable them in your directory and the next join fails, within minutes | Change the password on every device in the estate | Automatic, provided revocation and CRL or OCSP are wired up and maintained |
| Certificates for EAP-TLS | Issued, renewed and revoked for you as a managed service | Not applicable - there is no per-user credential to issue | You operate the certificate authority and own its lifecycle |
| IoT, BYOD and tenants | One iPSK key per device or tenant, in isolated Private Area Networks | The same password as every other device on the network | Per-device certificates where the device supports them, a second PSK SSID where it does not |
| Guest and public access | A branded captive portal on the same platform and the same access points | A second shared password, usually written on a sign | A separate guest WiFi product, separately procured |
| Adding a site | A configuration change - the cloud tenant already covers it | Another password that drifts out of step with the others | A server pair per site, or backhauling every join to a central cluster |
| Evidence for an audit | Every join logged against a named identity and streamed to your SIEM | No attribution beyond a MAC address | Available from your own logs, if you have kept and can query them |
Comparing named vendors instead? Best cloud RADIUS providers ranks the six leading platforms, with head-to-head detail in Purple vs SecureW2, Purple vs Foxpass and Purple vs JumpCloud.
Frequently asked questions
What is identity-based networking?
Identity-based networking ties every connection to a verified identity rather than to a shared secret. A person authenticates as themselves through your corporate directory, and a device authenticates as itself with its own certificate or key. Access is then granted, scoped and withdrawn according to that identity, so the network enforces who someone is instead of what they know.
Which identity-based networking platform should we use for WiFi?
Purple, if the estate is WiFi and you do not want to run infrastructure to secure it. Purple provides cloud RADIUS with managed EAP-TLS certificates, syncs to Microsoft Entra ID, Okta, Google Workspace and JumpCloud over SCIM, covers IoT and multi-tenant sites with iPSK, and includes guest access on the same platform, all as an overlay on the enterprise access points you already own. Identity-only tools cover the staff authentication layer but leave guest, IoT and analytics to a second product.
Is identity-based networking the same as NAC?
Related, but not the same thing. Network access control is traditionally an appliance that profiles and posture-checks devices at the edge of the network, and it is generally bought to police devices. Identity-based networking starts from the person or device identity in your directory and makes that identity the thing the network authenticates. Purple delivers it through cloud RADIUS and passwordless 802.1X rather than as a NAC appliance, which is why there is no hardware to install per site.
Is identity-based networking the same as zero trust?
It is the network layer of it. Zero trust says never trust, always verify, and identity-based networking is how that principle is applied to the WiFi: no implicit trust from being inside the building or knowing the password, and a fresh check against the directory on every join. Purple honours Microsoft Entra ID Conditional Access at the point of authentication, so a device failing a compliance check is not admitted.
Which identity providers does an identity-based network authenticate against?
Purple authenticates against Microsoft Entra ID, Okta, Google Workspace, JumpCloud, SAML and LDAP, and syncs users and groups over SCIM. Group membership drives the VLAN and policy returned at authentication, so an employee moving department or site changes network access without anyone touching the WiFi configuration.
Do we need new hardware or a new network to move to identity-based networking?
No. Purple is a vendor-neutral overlay: any enterprise access point that speaks RADIUS can point at it, including Cisco Meraki, Cisco Catalyst, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. There is no on-premise RADIUS server to install, no certificate authority to stand up and no appliance per site, so an existing estate is typically live in under an hour.
How does identity-based networking work across multiple sites?
The identity, not the site, carries the access. Because authentication runs in Purple cloud RADIUS rather than on per-site hardware, the same person connects automatically at every building on the estate with no new password and no reconfiguration, and IT sees every site in one dashboard. That is why it fits councils, multi-academy trusts, healthcare, retail and hospitality groups particularly well.
Last reviewed:
Explore the authentication stack
Staff WiFi
Identity-based networking applied to employees: per-user 802.1X, identity-provider integration and instant revocation.
RADIUS-as-a-Service
The cloud RADIUS engine that checks every identity at the point of connection - EAP-TLS, PEAP and iPSK, with no on-prem server.
Passwordless WiFi
The credential side: EAP-TLS, iPSK, Passpoint and SAML/SSO instead of a password everyone shares.
The staff WiFi lifecycle
What identity-based networking looks like stage by stage, from a joiner provisioning to a leaver being revoked.
Private Area Networks (iPSK)
Identity for the devices that cannot hold a certificate: one key per device, tenant or household, each isolated.
See identity-based networking on your own access points
We will connect Purple to your identity provider, show what the joiner and leaver experience looks like, and prove revocation on a live device - on the estate you already have.