CORE CONCEPTS 11 min read

What is Passpoint WiFi (Hotspot 2.0)? A Technical Overview

Understanding the IEEE 802.11u standard, ANQP, and how Passpoint enables automatic, secure network discovery and selection at scale.

Infiroam Technical Guides
Updated January 2026
EXECUTIVE SUMMARY

Passpoint (Hotspot 2.0) eliminates the need for users to manually select networks or interact with captive portals. It enables automatic, secure connectivity based on policy, significantly reducing support tickets and improving the end-user experience in high-density environments like universities, airports, and hotels.

Key business impact: 70-85% reduction in Wi-Fi related helpdesk tickets and faster, more secure onboarding for thousands of users simultaneously.

KEY TAKEAWAYS FOR DECISION MAKERS
  • • Removes captive portals for modern devices → dramatically better user experience
  • • Works best when paired with certificate-based authentication (EAP-TLS)
  • • Biggest wins in high-density or high-turnover environments (universities, airports, hotels)
  • • Requires upfront investment in identity integration and device profile management

The Problem with Traditional Wi-Fi Discovery

For years, public and guest Wi-Fi has relied on a fundamentally manual and fragile model. Users scan for SSIDs, connect to an open or PSK network, and are then redirected through a captive portal to authenticate or accept terms. This process is slow, inconsistent across devices and operating systems, and creates significant operational overhead for network teams.

More importantly, it introduces security and user experience problems: shared pre-shared keys, phishing risks on captive portals, and high volumes of support tickets during peak usage periods (such as university move-in or large events).

Modern secure WiFi connectivity in enterprise environment

Passpoint enables seamless, automatic connection without user intervention.

What is Passpoint?

Passpoint, also known as Hotspot 2.0, is a Wi-Fi Alliance certification program based on the IEEE 802.11u standard. Its primary goal is to enable automatic, secure, and seamless Wi-Fi network discovery, selection, and authentication for client devices.

Instead of users manually choosing networks and entering credentials, Passpoint allows devices to automatically identify suitable networks based on policy and then authenticate using modern methods (typically 802.1X/EAP) without ever presenting a captive portal to the user.

Core Technical Components

Passpoint Connection Flow (Simplified)
1. Detect
Client sees Passpoint support
2. ANQP Query
Asks network capabilities
3. Policy Match
Device evaluates profiles
4. 802.1X Auth
EAP-TLS certificate
5. Connected
IP + seamless access

How Passpoint Works in Practice

When a Passpoint-enabled client enters the coverage area of a compatible network:

  1. The client passively or actively discovers the network and detects that it supports Passpoint via beacon or probe response information.
  2. The client sends an ANQP query (via GAS) to learn detailed capabilities.
  3. The network responds with information about authentication methods, roaming partners, and other attributes.
  4. The client evaluates the response against its configured policies.
  5. If a match is found, the client automatically initiates 802.1X authentication (often using a previously provisioned certificate or credential).
  6. Upon successful authentication, the client receives an IP address and has full network access — all without any user interaction or captive portal.

Relevance for Enterprise and Public Venue Operators

Passpoint delivers the most value in environments with high user density and frequent onboarding events:

High-Impact Environments
  • • Universities and colleges (semester start)
  • • Airports and transportation hubs
  • • Large stadiums and convention centers
  • • Multi-property hotel groups
Business Outcomes
  • • Dramatic reduction in helpdesk tickets
  • • Improved guest and user satisfaction scores
  • • Stronger security posture (no shared secrets)
  • • Better support for global roaming (via OpenRoaming)
FOR TECHNICAL TEAMS

Passpoint and Certificate-Based Authentication

“The real power of Passpoint shows up when you stop asking users to do anything at all.”

While Passpoint can technically work with other EAP methods (such as EAP-PEAP or EAP-TTLS), the combination of Passpoint + EAP-TLS (certificate-based) is considered the gold standard for security and user experience in enterprise and public deployments.

With EAP-TLS, each device receives a unique X.509 certificate. Authentication becomes mutual and cryptographic. There are no passwords to share, forget, or reset. When properly integrated with a modern PKI (often delivered as PKI as a Service), certificate lifecycle management can be largely automated.

Key Technical Considerations for IT Leaders

  • Client Device Support — Modern Windows, macOS, iOS, and Android devices have good native Passpoint support. Legacy devices may require alternative onboarding paths during transition.
  • Profile Provisioning — Devices need a Passpoint profile (and ideally a certificate) before they can take advantage of automatic connection. This is often handled via MDM for managed devices and self-service portals for BYOD.
  • RADIUS and Identity Integration — Passpoint deployments require a robust RADIUS infrastructure that can validate certificates and map them to appropriate authorization policies.
  • Roaming Agreements — For organizations that want to offer or consume global roaming, integration with the Wireless Broadband Alliance (WBA) OpenRoaming federation becomes relevant.
Next Steps

Passpoint is most powerful when combined with a strong certificate strategy. Many organizations begin their evaluation by reading our guide on Deploying PKI as a Service for Quick EAP-TLS Onboarding.

Seeing Passpoint opportunities in your environment?
Get a short, independent assessment of where it would deliver the most value for your organization.
Was this guide useful?
Need help evaluating Passpoint for your environment?

Get independent, technical recommendations tailored to your scale, identity systems, and device fleet.

RELATED GUIDES