Replace a shared guest Wi-Fi password with Cloudi-Fi. Set up employee SAML login, visitor registration, access policies, and pilot testing.
Cloudi-Fi Captive Portal offers separate login methods for employees and visitors. Employees authenticate with their corporate identity. Visitors follow the selected registration or approval process. Both groups receive the access defined for their role.
Use case
This approach applies when a visitor password circulates among employees, while personal internet access remains an approved service. The goal is to identify users and apply the right policies without removing employee personal access. Corporate devices can continue to use their existing network.
One Service Set Identifier (SSID), or wireless network name, can serve visitors and employee personal devices. Separate login methods and profiles distinguish the two groups. The network configuration determines how their traffic is controlled.
Figure 1. Example target design. A common portal serves employees and visitors while corporate devices retain their existing network.
Prerequisites
- Access to the Cloudi-Fi administration console and the wireless network configuration
- A supported captive portal integration for the wireless platform and software version
- An employee identity provider, such as Microsoft Entra ID
- A selected visitor registration or approval method
- Agreed access rules, session durations, and a pilot site with a rollback plan
The following steps describe the setup approach. Use the linked configuration guides for the settings specific to the identity provider and network platform.
Step 1 Define the two access profiles
Define an employee personal-device profile and a visitor profile. For each, record who can connect, which destinations are allowed, and how long access lasts. Identify any devices that currently depend on the shared password before scheduling its removal.
For example, both groups may receive internet access while internal systems remain protected. An employee login identifies the person; it does not establish that a personal device is managed or approved for corporate network access.
Step 2 Configure employee authentication
Enable employee sign-in through Security Assertion Markup Language (SAML). The portal redirects the employee to the corporate identity provider, which handles authentication. Cloudi-Fi applies the profile configured for that identity.
For Microsoft Entra ID, follow the Cloudi-Fi SAML configuration guide. Configure the application, exchange the required settings, and map employees to the intended profile. Confirm that the portal and required identity-provider destinations are reachable before login.
Test the employee SAML login journey on representative personal devices. An authorized employee should receive the employee profile. A user without the required access should not receive it.
Step 3 Configure visitor registration
Select email registration, SMS registration, or sponsorship according to the visitor access policy. Sponsorship suits sites where a host must approve access. Self-registration suits sites that allow visitors to register directly under defined conditions.
Set the information required, the validation or approval process, and the account duration. Use clear portal labels so employees select the employee login method. Treat a typed name or email address as verified only when the chosen process actually verifies it.
Step 4 Apply access and session policies
Configure each control for its intended purpose.
- Registration policies govern registration conditions and available profile choices.
- Access control policies allow or deny authentication based on criteria such as profile, location, and time.
- Privilege policies define supported session settings, including duration and simultaneous device limits.
Figure 2. Policy responsibilities. Identity and session controls work alongside the wireless network and security gateway.
The wireless and security infrastructure enforces the permitted traffic path. Confirm that the selected integration applies the network treatment required for each group. A portal profile alone does not demonstrate that the traffic rules are correct.
Also validate wireless encryption when retiring the pre-shared key (PSK). An HTTPS portal protects the web exchange, but does not itself encrypt the radio link. Select a wireless security mode compatible with the infrastructure, devices, and portal integration. Cisco’s wireless security and web authentication guidance explains this distinction.
Step 5 Validate the pilot
Run these checks before retiring the shared-password service.
- Employees and visitors complete their respective login or registration process.
- Each group receives the intended profile and session duration.
- Permitted internet services work, and protected internal resources remain inaccessible where required.
- Expiry and reauthentication follow the agreed policy.
- Support can find the sessions and identify the site and user.
- Corporate devices continue to use their existing network.
Record failed checks and resolve them before expanding the rollout. Confirm how to restore approved access if the pilot fails.
Step 6 Retire the shared password
Communicate the new connection process and cutover date to employees, reception, and support. Retire the old shared-password service after the pilot passes. Remove obsolete instructions and confirm that no required device still depends on the old service.
Set an end date for any temporary network used during migration. A rollback should restore controlled access rather than leave a widely circulated password permanently available.
Troubleshooting
If the portal or employee sign-in page does not open, check redirection and access to the required destinations before authentication. If an employee receives the wrong profile, check SAML profile mapping. If login works but network access is incorrect, check the applied profile, session settings, and network security rules.
Expected result
Employees retain approved personal internet access, and visitors use a defined registration or approval process. The shared password no longer determines who can connect. The Cloudi-Fi Captive Portal provides the common entry point, with identity and policy controlling the access that follows.