Passpoint (Hotspot 2.0) eliminates the need for users to manually select networks or interact with captive portals. It enables automatic, secure connectivity based on policy, significantly reducing support tickets and improving the end-user experience in high-density environments like universities, airports, and hotels.
Key business impact: 70-85% reduction in Wi-Fi related helpdesk tickets and faster, more secure onboarding for thousands of users simultaneously.
- • Removes captive portals for modern devices → dramatically better user experience
- • Works best when paired with certificate-based authentication (EAP-TLS)
- • Biggest wins in high-density or high-turnover environments (universities, airports, hotels)
- • Requires upfront investment in identity integration and device profile management
The Problem with Traditional Wi-Fi Discovery
For years, public and guest Wi-Fi has relied on a fundamentally manual and fragile model. Users scan for SSIDs, connect to an open or PSK network, and are then redirected through a captive portal to authenticate or accept terms. This process is slow, inconsistent across devices and operating systems, and creates significant operational overhead for network teams.
More importantly, it introduces security and user experience problems: shared pre-shared keys, phishing risks on captive portals, and high volumes of support tickets during peak usage periods (such as university move-in or large events).
Passpoint enables seamless, automatic connection without user intervention.
What is Passpoint?
Passpoint, also known as Hotspot 2.0, is a Wi-Fi Alliance certification program based on the IEEE 802.11u standard. Its primary goal is to enable automatic, secure, and seamless Wi-Fi network discovery, selection, and authentication for client devices.
Instead of users manually choosing networks and entering credentials, Passpoint allows devices to automatically identify suitable networks based on policy and then authenticate using modern methods (typically 802.1X/EAP) without ever presenting a captive portal to the user.
Core Technical Components
- Access Network Query Protocol (ANQP) — A query/response protocol that allows a client to request detailed network capability information before association. This includes supported EAP methods, roaming consortiums (for inter-operator roaming), venue information, and IP address availability.
- Generic Advertisement Service (GAS) — The transport mechanism (using 802.11 public action frames) that carries ANQP queries and responses between client and access point.
- 802.1X / EAP Authentication — Passpoint networks almost always use enterprise authentication rather than open or PSK. EAP-TLS (certificate-based) is the strongest and most common method for production deployments.
- Policy-based Network Selection — Devices can be configured with profiles that define which networks they should prefer based on organizational policy, roaming agreements, or service level.
How Passpoint Works in Practice
When a Passpoint-enabled client enters the coverage area of a compatible network:
- The client passively or actively discovers the network and detects that it supports Passpoint via beacon or probe response information.
- The client sends an ANQP query (via GAS) to learn detailed capabilities.
- The network responds with information about authentication methods, roaming partners, and other attributes.
- The client evaluates the response against its configured policies.
- If a match is found, the client automatically initiates 802.1X authentication (often using a previously provisioned certificate or credential).
- Upon successful authentication, the client receives an IP address and has full network access — all without any user interaction or captive portal.
Relevance for Enterprise and Public Venue Operators
Passpoint delivers the most value in environments with high user density and frequent onboarding events:
- • Universities and colleges (semester start)
- • Airports and transportation hubs
- • Large stadiums and convention centers
- • Multi-property hotel groups
- • Dramatic reduction in helpdesk tickets
- • Improved guest and user satisfaction scores
- • Stronger security posture (no shared secrets)
- • Better support for global roaming (via OpenRoaming)
Passpoint and Certificate-Based Authentication
“The real power of Passpoint shows up when you stop asking users to do anything at all.”
While Passpoint can technically work with other EAP methods (such as EAP-PEAP or EAP-TTLS), the combination of Passpoint + EAP-TLS (certificate-based) is considered the gold standard for security and user experience in enterprise and public deployments.
With EAP-TLS, each device receives a unique X.509 certificate. Authentication becomes mutual and cryptographic. There are no passwords to share, forget, or reset. When properly integrated with a modern PKI (often delivered as PKI as a Service), certificate lifecycle management can be largely automated.
Key Technical Considerations for IT Leaders
- Client Device Support — Modern Windows, macOS, iOS, and Android devices have good native Passpoint support. Legacy devices may require alternative onboarding paths during transition.
- Profile Provisioning — Devices need a Passpoint profile (and ideally a certificate) before they can take advantage of automatic connection. This is often handled via MDM for managed devices and self-service portals for BYOD.
- RADIUS and Identity Integration — Passpoint deployments require a robust RADIUS infrastructure that can validate certificates and map them to appropriate authorization policies.
- Roaming Agreements — For organizations that want to offer or consume global roaming, integration with the Wireless Broadband Alliance (WBA) OpenRoaming federation becomes relevant.
Passpoint is most powerful when combined with a strong certificate strategy. Many organizations begin their evaluation by reading our guide on Deploying PKI as a Service for Quick EAP-TLS Onboarding.