Think about how your phone behaves when you land in a new city. You switch off airplane mode and within seconds you're on a cellular network — authenticated, encrypted, and billed correctly — without typing anything. Now think about Wi-Fi at that same airport: pick a network name, hope it's the real one, click through a splash page, maybe enter an email address.

Passpoint and OpenRoaming exist to make Wi-Fi work like cellular. For facility owners and IT leaders, they're becoming the standard way to deliver secure, frictionless connectivity in buildings.

What is Passpoint?

Passpoint is a Wi-Fi Alliance certification program, also known by its underlying spec name, Hotspot 2.0. It lets a device automatically discover and securely join Wi-Fi networks where it holds a valid credential — without the user choosing a network name.

It works in three steps:

  1. A credential is installed on the device. This can be the phone's carrier SIM, a profile from an employer or school, or a profile from a service provider. Many phones ship with carrier Passpoint profiles already in place.
  2. The device asks before it joins. Using the Access Network Query Protocol (ANQP), the device queries nearby access points about which identity providers and roaming partners they support — before associating.
  3. It authenticates with enterprise-grade security. If there's a match, the device authenticates using 802.1X/EAP, and the session is encrypted with unique keys. SIM credentials use EAP-SIM, EAP-AKA, or EAP-AKA′ — the same family of mechanisms used on cellular networks.

What is OpenRoaming?

OpenRoaming is a federation run by the Wireless Broadband Alliance. It connects identity providers (carriers, device makers, cloud identity platforms, enterprises) with access network providers (venues, campuses, cities) under one set of rules and one trust framework.

When an organization joins, the federation issues it certificates so that every member can mutually authenticate and every bit of signaling across the federation is secured. The result: a user with a credential from any participating identity provider can connect automatically and securely to any participating network — millions of them worldwide.

Put simply: Passpoint is the technology; OpenRoaming is the global agreement that lets it work across organizations.

Why it's considered secure

The WBA's 2026 Wi-Fi Security FAQ highlights several reasons Passpoint and OpenRoaming represent a step change for public Wi-Fi:

  • Evil twins can't fake it. Authentication only succeeds if the network can securely reach the user's credential provider. A rogue access point can't, so the device won't proceed.
  • Credentials are protected end to end. With EAP correctly configured for server validation, the device only sends its credentials over a secure tunnel to its own identity provider — even before the Wi-Fi link is encrypted.
  • Every session gets its own keys. Unlike shared-passphrase networks, each device's link encryption is unique.
  • Humans are removed from network selection. No choosing between “Free_WiFi” and “Free_WiFi_2,” and no captive portals — two of the most common attack vectors.

Nothing is 100% secure, and the WBA says so directly. But combined with updated devices and sensible network design, Passpoint delivers enterprise-grade security in public environments.

What it means for venues and enterprises

Better guest experience

Visitors connect automatically and securely. No splash pages, no support calls about “the Wi-Fi password,” no devices that can't get through a portal.

Carrier-grade connectivity over Wi-Fi

Because Passpoint supports SIM-based authentication, carriers can authenticate their own subscribers on a building's Wi-Fi. That's the foundation for delivering reliable indoor voice and data coverage over existing Wi-Fi infrastructure, instead of building an expensive Distributed Antenna System.

Less operational overhead

Fewer SSIDs, fewer passphrases to rotate, and fewer helpdesk tickets. Identity lives with the identity provider, not on a sticky note.

What you need to deploy it

  • Passpoint-capable access points and controllers. Most current enterprise platforms — Cisco Meraki, HPE Aruba, RUCKUS, Ubiquiti UniFi, and others — support it, though configuration depth varies.
  • A secure path to identity providers, typically RADIUS over TLS (RadSec) via a roaming hub or proxy.
  • Policies and agreements with the carriers or federations whose users you want to serve.
  • Segmentation and monitoring, as with any production network.

The hardest part for most organizations isn't the access points — it's the carrier and federation integration. That's where an experienced partner saves months.

The bottom line

Passpoint and OpenRoaming turn Wi-Fi into something closer to cellular: automatic, identity-based, and encrypted by default. For any building where people expect their phones to just work, they're quickly becoming the baseline rather than the exception.

Source material: Wireless Broadband Alliance, Wi-Fi Security – General Audience FAQ, v1.0.0 (April 2026). Passpoint® is a registered trademark of Wi-Fi Alliance. OpenRoaming™ is a trademark of the Wireless Broadband Alliance.