Skip to content
EasyPSK via RADIUS

Groups and security flavours

An EasyPSK group maps one Wi-Fi key to a set of devices. The security flavour — Instant, Approved, or Dedicated — sets how strict device onboarding is, and is locked once the group has its first device.

A group in an EasyPSK Context maps one Wi-Fi pre-shared key to a set of devices — up to 30 devices per group. When you create the group you choose how strict device onboarding should be — you can dial it up later, but only while the group still has no devices.

Open the Context and click Add Group. The form has two parts:

  • Identity — the Group name, shown to admins and used to label devices that join with this group’s key.
  • Security flavour — a three-position slider. Slide to balance friction against security; the choice is locked once the group has its first device.
Create an EasyPSK group form with the Security flavour slider showing Instant, Approved, and Dedicated positions
Create an EasyPSK group: name plus the security-flavour slider (here on Dedicated).
InstantApprovedDedicated
TaglineFrictionlessPre-registeredPer-device key
Key modelOne group keyOne group keyA unique key per device
Device onboardingAuto-registered on first connectMAC must be pre-registered; a correct key is otherwise rejected. Optional four-eyes approvalMAC pre-registered together with its unique key; both must match
Best forFriction-free co-working and residential unitsGroups where only known devices may joinThe strictest environments and headless fleets
  • Instant — devices connect with the group key and are auto-registered: no pre-registration. Best for friction-free co-working and residential use.
  • Approved — devices must be pre-registered. A correct key is rejected unless the device’s MAC is already registered in the group. With four-eyes device approval enabled, a second administrator must also acknowledge each registration.
  • Dedicated — a unique key per device. Pre-register the device’s MAC; both the MAC and the device’s own key must match at connect time. There is no shared group key at all.

The platform generates every key. Keys are unique within the EntryPoint and regenerate-only: users never choose them. The key is what identifies the group at connect time — “one key, the right group”.

On Approved groups you can require that each device registration is acknowledged by a second administrator before the device is admitted. The first administrator registers the device’s MAC; the device stays pending until another administrator approves it, and until then it is rejected at connect time even with the correct key. Use it where device admission is a controlled decision: finance floors, labs, or any environment where one person should not be able to admit hardware alone.

Each group also carries a set of group controls: a device cap, a validity window, a recurring schedule, and a device block list. They apply on top of the flavour, so a correct key only admits a device that also passes the group’s controls.

Each group has stat cards (Users — self-service members, Devices — registered in the group, Online) and five tabs: Connected Devices, MAB Device List, Self-Service Users, Group Settings, and Authentication Log.

Vandelay Dorms context overview with nine room groups across the Instant, Approved, and Dedicated flavours, 31 registered devices and 17 online
The groups list shows each group's flavour next to its name.
Group Settings tab with Security flavour card, masked Pre-shared key with Reveal, Copy, and Regenerate PSK, and the Self-service PSK regeneration card
Group Settings for an Instant group: the flavour, the regenerate-only key, and the self-service rotation toggle.
  • Security flavour — shows the group’s flavour. It stays editable until the first device connects, then locks.
  • Pre-shared key (Instant and Approved) — the group’s key, masked with Reveal and Copy controls. Regenerate PSK disconnects every device still using the current key; they reconnect with the new one.
  • Per-device keys (Dedicated) — there is no shared group key to reveal or regenerate. Each device has its own unique key, managed from the device list.
  • Self-service PSK regeneration — a toggle that lets the group’s Self-Service members rotate the shared key themselves from the Self-Service portal. For Dedicated groups the toggle does not apply, since rotation happens per device.
Group Settings for a Dedicated group showing the Per-device keys card and the self-service regeneration card disabled
A Dedicated group: per-device keys instead of a shared group key.

Invite residents or team members from the Self-Service Users tab. From the Self-Service portal they can see the SSID and their group’s key, and — if you enabled self-service regeneration — rotate it. In Dedicated groups, device keys are issued and rotated per device instead.

Next