ROAMING & FEDERATION

OpenRoaming and Passpoint: Extending University Identity Across Cities and Transport Networks

How universities can use Passpoint profiles and dedicated onboarding platforms to let students authenticate seamlessly on OpenRoaming networks far beyond campus — from city stations to airports and partner venues.

EXECUTIVE SUMMARY

OpenRoaming is a global federation built directly on Passpoint (Hotspot 2.0) technology. While Passpoint enables automatic, secure discovery and connection at the radio level, OpenRoaming adds the trust framework, standardized identifiers, and RadSec (RADIUS over TLS) that lets a university’s existing identity system authenticate students on thousands of participating networks worldwide.

For universities, this means students carrying a properly provisioned Passpoint profile can connect automatically and securely using their campus credentials or certificates at airports, public transport stations, city Wi-Fi zones, and partner locations — without captive portals, without new accounts, and without the university having to manage separate agreements with every venue.

The critical missing piece for most campuses is not the federation itself, but the ability to intelligently create and deliver the correct OpenRoaming-enabled Passpoint profiles at scale, together with the RadSec connectivity that ties remote networks back to the university’s identity provider. A dedicated onboarding and dynamic PKI platform, paired with your existing AAA infrastructure, makes this practical and maintainable for large student and staff populations.

KEY TAKEAWAYS FOR DECISION MAKERS

Passpoint and OpenRoaming: The Relationship

Passpoint (also known as Hotspot 2.0 or 802.11u) is the Wi-Fi Alliance standard that lets devices automatically discover networks, evaluate policy, and connect securely before the user does anything. It uses ANQP queries to learn about available networks and supports advanced policy elements such as Roaming Consortium Organization Identifiers (RCOI).

OpenRoaming, managed by the Wireless Broadband Alliance (WBA), takes Passpoint and turns it into a global roaming service. It defines a federation of Identity Providers (IdPs) — such as universities — and Access Network Providers (ANPs) — such as transport operators, airports, cities, and venues. Devices that hold the correct OpenRoaming-enabled Passpoint profile can connect automatically at any participating network.

In short: Passpoint is the car. OpenRoaming is the global highway system with standardized rules, trust, and billing/settlement frameworks (when used commercially).

Infographic showing how a university uses a dedicated onboarding platform to issue Passpoint profiles with OpenRoaming RCOI and connect via RadSec to remote networks at transport stations, airports, and city locations

The university identity (via existing AAA) reaches far beyond campus when Passpoint profiles and RadSec are properly enabled through a dedicated onboarding layer.

How Universities Extend Their Identity

Most universities already have strong identity systems (Entra ID, Okta, campus directories) and RADIUS/AAA infrastructure that powers eduroam or campus Wi-Fi. OpenRoaming lets them reuse that investment outside traditional eduroam venues.

The practical flow for a student looks like this:

  1. The student receives a Passpoint profile (ideally via a dedicated self-service onboarding flow) that includes the OpenRoaming RCOI and the university’s trusted server certificate information.
  2. When the student arrives at a participating OpenRoaming venue (train station, airport, city zone), the device uses ANQP to discover the network and matches the RCOI in its profile.
  3. The venue’s network (ANP) initiates authentication using RadSec — a secure TLS-protected connection — to reach the university’s IdP or a proxy that speaks for it.
  4. The university authenticates the student using their existing credential or certificate and returns the appropriate authorization decision.
  5. The student is online with enterprise-grade security, no captive portal, and no new login.

This is especially powerful for universities because students move constantly between campus, home, transport, and other cities. A single profile can keep them connected across that entire journey.

University student with phone automatically connected via OpenRoaming while walking through a busy public transport station on the way to or from campus

Students experience seamless connectivity from campus networks through public transport and city locations when OpenRoaming is enabled with the right profiles.

The Role of Dedicated Onboarding Platforms

Manually creating and distributing OpenRoaming-capable Passpoint profiles to tens of thousands of student and staff devices is impractical. Native tools and basic MDM often lack the precision needed for the correct RCOIs, NAI realms, and certificate trust anchors that OpenRoaming requires.

A dedicated onboarding and dynamic PKI platform solves this by:

The onboarding layer works with — rather than replaces — the university’s existing AAA and identity systems. It supplies the profiles and often the federation connectivity, while the core authorization decisions stay with the systems the university already trusts.

Driving Meaningful Collaboration

OpenRoaming creates natural, high-value partnerships for universities because the benefit is immediate and visible to students and staff.

One of the strongest examples is public transport. Universities can work with local rail, bus, and metro operators to turn major stations and vehicles into OpenRoaming ANPs. A student leaving their residence hall or apartment can stay connected on the journey to campus without switching networks or re-authenticating. The same profile works at the destination airport when they travel for conferences, internships, or visits home.

Other high-impact collaborations include:

These partnerships are easier to justify than traditional guest Wi-Fi arrangements because the security model is strong (certificate-based or federated authentication with RadSec), the user experience is automatic, and the university retains control over who can connect.

For Technical Teams: Practical Considerations

  • Profile configuration: Ensure Passpoint profiles distributed to devices include the WBA OpenRoaming RCOI(s) in addition to any campus-specific RCOIs. Test both discovery and authentication flows.
  • RadSec readiness: Your AAA or a dedicated platform must support RadSec (RADIUS over TLS) with proper certificate trust for the WBA/OpenRoaming PKI. Many modern cloud RADIUS services make this straightforward.
  • IdP integration: Decide whether the university will act directly as an OpenRoaming IdP or use a proxy/hub. Dedicated onboarding platforms often simplify the proxy route while keeping policy decisions local.
  • Fallback and legacy support: Not every venue a student visits will support OpenRoaming. Maintain a clear, low-friction path (such as a secondary onboarding option) for locations that are not yet participating.
  • Monitoring and policy: Track authentication success from remote OpenRoaming networks. Use the same policy engine you already have for campus and eduroam to decide what remote users are allowed to do.
  • Testing the full journey: Validate end-to-end from a student device at a real transport hub or airport back to the university IdP before wide rollout.

Because profile management and much of the federation connectivity can live in the dedicated onboarding layer, changes to which RCOIs you honor or which partners you add become configuration updates rather than massive device or infrastructure projects.

Bottom Line for Universities

OpenRoaming turns Passpoint from a campus or local roaming technology into a practical way to extend the university’s identity across the places students and staff actually travel. When combined with a dedicated onboarding platform capable of provisioning the right profiles and supporting RadSec, universities can deliver the kind of seamless, secure connectivity users now expect — from the moment they leave home until they return to campus — while creating valuable collaborations with transport providers, airports, and local partners.

The technology has matured, the federation is growing, and the operational pieces are increasingly accessible through modern onboarding and PKI layers that work alongside the AAA infrastructure universities already own.

Was this guide useful?
Related guides: Passpoint vs Traditional Wi-Fi: Your Existing Infrastructure Is ReadyDeploying Passpoint and Modern Onboarding in High-Density University EnvironmentsPairing Modern Onboarding with AAA for University BYODWhat is Passpoint WiFi?Deploying PKI as a Service for Quick EAP-TLS