Multiple Password Option for a Single SSID

I have a situation where outside agencies utilize our access points with their agency provided VPN to connect to their agency’s network. As such, I do not have administrative control of these computers to update WiFi passwords remotely when we periodically change our SSID passwords.

It would be great if each SSID had the capability to have multiple (at least two) passwords assigned. This would allow users to connect via the legacy password until Windows group policy objects are pushed to the users’ machines. Once all machines have updated, the legacy password for the SSID could be deleted can be deleted from the access point’s configuration. This capability would greatly reduce, if not eliminate, user downtime during periodic password changes.

During subsequent periodic SSID password changes, the domain administrators would be provide with the new password to update their GPOs and users would still be able to connect to our access points with the old passwords until their machines update their GPOs.

They do, using PPSK. Its a powerful feature that has lots of great uses cases, and you can even steer users for a particular password to different VLANs.

Setup in IC2:
**


**

It has to be WPA2 btw, as the way key exchange works for WPA3 precludes the ability to do this.

Its fantastic for IOT devices that don’t support enterprise wifi. For your use case, you could configure a different password for external agency, so you could control the access for each one separately (i.e. end one of them if they left etc without affecting the others)