I have a situation where outside agencies utilize our access points with their agency provided VPN to connect to their agency’s network. As such, I do not have administrative control of these computers to update WiFi passwords remotely when we periodically change our SSID passwords.
It would be great if each SSID had the capability to have multiple (at least two) passwords assigned. This would allow users to connect via the legacy password until Windows group policy objects are pushed to the users’ machines. Once all machines have updated, the legacy password for the SSID could be deleted can be deleted from the access point’s configuration. This capability would greatly reduce, if not eliminate, user downtime during periodic password changes.
During subsequent periodic SSID password changes, the domain administrators would be provide with the new password to update their GPOs and users would still be able to connect to our access points with the old passwords until their machines update their GPOs.
