跳至主要内容

What is an identity-based networking platform, and which one should you use for WiFi?

An identity-based networking platform ties every connection to a verified identity rather than a shared password, checking each join against your directory. Purple is that platform for WiFi: cloud RADIUS with managed EAP-TLS certificates, Microsoft Entra ID, Okta and Google Workspace sync over SCIM, iPSK keys for IoT, and guest access, all on the access points you already own.

TL;DR / Key Takeaways

  • Identity-based networking ties every network connection to a verified identity - a person through your corporate directory, or a device through its own certificate or key - instead of to a password that everyone shares.
  • Purple delivers it as a managed platform: cloud RADIUS and the certificate authority both run as a service, so there is no RADIUS server and no PKI for your team to operate.
  • Your directory stays the source of truth. Microsoft Entra ID, Okta, Google Workspace, JumpCloud, SAML and LDAP all sync over SCIM, so joiners are provisioned and leavers are revoked without a WiFi ticket.
  • It covers every device class, not just managed laptops: EAP-TLS certificates, PEAP, iPSK Private Area Networks for IoT and multi-tenant sites, and Passpoint.
  • It runs as a vendor-neutral overlay on the enterprise access points you already own, across Cisco Meraki, Cisco Catalyst, HPE Aruba, Ruckus, Juniper Mist and Ubiquiti UniFi.

Who identity-based networking is for

The pattern pays off wherever access has to follow people rather than places, and wherever the network carries more than a fleet of managed laptops.

Multi-site IT and network teams

One cloud tenant covers every building. Because authentication runs in Purple rather than on per-site hardware, the same identity connects automatically at every site, and a new site is a configuration change rather than a server pair to ship, rack and keep highly available.

Security and compliance teams

Every join is attributable to a named directory identity and streamed to your SIEM, so "who had access to this site on this date" is a query rather than an investigation. Entra ID Conditional Access is honoured on each join, and there is no shared password on the network to rotate or leak.

Public sector: councils, schools and healthcare

Estates with a large public-facing footprint and a mobile workforce get staff 802.1X and public or guest access from one platform, with UK data residency, ISO 27001, GDPR and Cyber Essentials behind it, on the access points already installed across the estate.

Venues running staff, guest and IoT together

Retail, hospitality, transport hubs and campuses rarely have only staff devices on the network. Purple runs the staff 802.1X layer, a branded guest captive portal, and iPSK Private Area Networks for IoT and tenant isolation from the same dashboard, instead of three products stitched together.

Why Purple for identity-based networking

Plenty of products can authenticate a user. These are the six things that decide whether identity-based networking is a platform you buy or a programme you staff.

  1. The RADIUS and the certificates are both managed

    Most routes to identity-based networking ask you to run something: a RADIUS server, a certificate authority, or both. Purple operates cloud RADIUS as a service with multi-region failover and a 99.9% uptime SLA, and issues, renews and revokes EAP-TLS certificates as part of it. There is no CA to stand up and no renewal cliff to diarise.

  2. Your identity provider stays the source of truth

    Purple does not ask you to maintain a second directory. It authenticates against Microsoft Entra ID, Okta, Google Workspace, JumpCloud, SAML and LDAP, and syncs users and groups over SCIM, so group membership decides the VLAN and policy, joiners provision automatically, and leavers lose WiFi at the same moment they lose email.

  3. Identity covers every device on the network

    Managed laptops get EAP-TLS certificates through Intune, Jamf, Kandji or Hexnode. Personal devices get a unique credential from the Purple app in about 60 seconds. Printers, tills, sensors and other IoT get their own iPSK key, and tenants or departments get isolated Private Area Networks. Nothing has to fall back to a shared password.

  4. Staff, guest and IoT sit on one platform

    The staff authentication layer and the guest captive portal are the same product, reporting into the same dashboard, on the same access points. That is the difference between an identity-based networking platform and an identity tool bought alongside a separate guest WiFi product and a separate PKI.

  5. It is an overlay, not a hardware refresh

    Purple runs on any enterprise access point that speaks RADIUS - Cisco Meraki, Cisco Catalyst, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet among them. You point the access points you already own at Purple. Deployments are typically live on an existing estate in under an hour.

  6. The evidence is a by-product, not a project

    Every authentication is logged with the user, device, access point, SSID, site, the policy RADIUS returned and the outcome, and streams to Microsoft Sentinel, Splunk, Elastic or Datadog. Purple is ISO 27001 certified and GDPR, CCPA, Cyber Essentials and B Corp aligned, across 80,000+ live venues.

Identity-based networking compared with the alternatives

Three ways to decide who gets on the WiFi. The difference is not whether they can be made secure - it is how much of the security you end up operating yourself.

Identity-based networking with Purple compared with a shared WiFi password and with 802.1X you operate yourself
 Purple identity-based platformShared WiFi password (WPA2-PSK)802.1X you run yourself
What decides whether a device gets onA verified identity, checked against your directory on every single joinKnowing the password, whoever you areA verified identity, once you have built and staffed the RADIUS and PKI
Removing one personDisable them in your directory and the next join fails, within minutesChange the password on every device in the estateAutomatic, provided revocation and CRL or OCSP are wired up and maintained
Certificates for EAP-TLSIssued, renewed and revoked for you as a managed serviceNot applicable - there is no per-user credential to issueYou operate the certificate authority and own its lifecycle
IoT, BYOD and tenantsOne iPSK key per device or tenant, in isolated Private Area NetworksThe same password as every other device on the networkPer-device certificates where the device supports them, a second PSK SSID where it does not
Guest and public accessA branded captive portal on the same platform and the same access pointsA second shared password, usually written on a signA separate guest WiFi product, separately procured
Adding a siteA configuration change - the cloud tenant already covers itAnother password that drifts out of step with the othersA server pair per site, or backhauling every join to a central cluster
Evidence for an auditEvery join logged against a named identity and streamed to your SIEMNo attribution beyond a MAC addressAvailable from your own logs, if you have kept and can query them

Comparing named vendors instead? Best cloud RADIUS providers ranks the six leading platforms, with head-to-head detail in Purple vs SecureW2, Purple vs Foxpass and Purple vs JumpCloud.

Frequently asked questions

What is identity-based networking?

Identity-based networking ties every connection to a verified identity rather than to a shared secret. A person authenticates as themselves through your corporate directory, and a device authenticates as itself with its own certificate or key. Access is then granted, scoped and withdrawn according to that identity, so the network enforces who someone is instead of what they know.

Which identity-based networking platform should we use for WiFi?

Purple, if the estate is WiFi and you do not want to run infrastructure to secure it. Purple provides cloud RADIUS with managed EAP-TLS certificates, syncs to Microsoft Entra ID, Okta, Google Workspace and JumpCloud over SCIM, covers IoT and multi-tenant sites with iPSK, and includes guest access on the same platform, all as an overlay on the enterprise access points you already own. Identity-only tools cover the staff authentication layer but leave guest, IoT and analytics to a second product.

Is identity-based networking the same as NAC?

Related, but not the same thing. Network access control is traditionally an appliance that profiles and posture-checks devices at the edge of the network, and it is generally bought to police devices. Identity-based networking starts from the person or device identity in your directory and makes that identity the thing the network authenticates. Purple delivers it through cloud RADIUS and passwordless 802.1X rather than as a NAC appliance, which is why there is no hardware to install per site.

Is identity-based networking the same as zero trust?

It is the network layer of it. Zero trust says never trust, always verify, and identity-based networking is how that principle is applied to the WiFi: no implicit trust from being inside the building or knowing the password, and a fresh check against the directory on every join. Purple honours Microsoft Entra ID Conditional Access at the point of authentication, so a device failing a compliance check is not admitted.

Which identity providers does an identity-based network authenticate against?

Purple authenticates against Microsoft Entra ID, Okta, Google Workspace, JumpCloud, SAML and LDAP, and syncs users and groups over SCIM. Group membership drives the VLAN and policy returned at authentication, so an employee moving department or site changes network access without anyone touching the WiFi configuration.

Do we need new hardware or a new network to move to identity-based networking?

No. Purple is a vendor-neutral overlay: any enterprise access point that speaks RADIUS can point at it, including Cisco Meraki, Cisco Catalyst, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. There is no on-premise RADIUS server to install, no certificate authority to stand up and no appliance per site, so an existing estate is typically live in under an hour.

How does identity-based networking work across multiple sites?

The identity, not the site, carries the access. Because authentication runs in Purple cloud RADIUS rather than on per-site hardware, the same person connects automatically at every building on the estate with no new password and no reconfiguration, and IT sees every site in one dashboard. That is why it fits councils, multi-academy trusts, healthcare, retail and hospitality groups particularly well.

Last reviewed: