Multi Pre-Shared Key (MPSK)

Overview of Multi Pre-Shared Key (MPSK) workflows in Central NAC

WPA2-PSK or pre-shared keys (PSK) are a common way to connect to WiFi networks. Admin sets up a password for WiFi network and then the password has to be entered in all the devices that need to connect. While very widely used, there are significant issues with WPA2-PSK. All devices use the same password and if its inadvertently leaked or compromised through attacks, the data exchanged between devices and the access point can be decrypted. The solution would be to change the password and this needs to be done manually on all the devices. Due to all these issues WPA2-PSK poses significant risks in an enterprise environment.

Multi Pre-Shared Key (MPSK) is a feature developed by HPE Aruba Networking to allow devices to connect securely using Wi-Fi credentials that are unique to a user or device or a group of devices. With each user or device having a unique MPSK, security is enhanced by limiting exposure if the PSK is compromised. Devices sharing similar functions can be grouped together and can share a single MPSK, thus simplifying management. MPSK improves the security profile of WPA2-PSK but without compromising on the ease of use. So this becomes a secure and easy way to connect devices where a full 802.1X deployment is not feasible.

Some common use cases with MPSK are:

  • IoT and other headless devices that are not capable of doing 802.1X authentication can now connect with a unique MPSK per device
  • Guest Wi-Fi for event networks that are short lived. QR codes can be printed and posted at the event venue for attendees to connect easily to the network
  • Easy way for students in dorm rooms to connect all their personal devices using a MPSK that is unique per student
  • Alternative to captive portal workflows for guest users with MPSKs being rotated periodically
  • Provides easy connectivity option at small sites where deploying 802.1X is not feasible

MPSK Workflows in Central NAC

HPE Aruba Networking Central NAC supports two modes for MPSK:

  • User Managed MPSK
  • Admin Managed MPSK

User Managed MPSK

This feature allows users to generate and manage their own unique MPSK through a self-service portal. Per user Wi-Fi credentials reduce the risk associated with single shared passwords. It also allows devices to be identified on the network by the user who owns them.

Some scenarios where user managed MPSK can be used:

  • dorm rooms where students want to connect their personal IoT devices
  • environments where BYOD users with unmanaged devices do not want to install an app to onboard the device
  • allowing contractors to connect their work devices
  • allowing employees at retail locations to connect their personal devices

How it works:

  1. User goes to the MPSK self service portal and signs in using credentials from the configured identity provider
  2. Portal generates a unique MPSK key for the user. The key can be in the form of a passphrase or a randomized password depending upon how the authentication profile is configured.
  3. User connects all their devices to the Wi-Fi using this MPSK
  4. Devices are assigned roles and VLANs based on the authorization policies configured in Central NAC. Devices owned by different types of users can be assigned different roles based on group membership in IDP.
  5. User can also regenerate their MPSK from the self service portal
  6. When a user account is deleted or disabled in the identity provider, all MPSKs associated with the user are deleted and active sessions are disconnected
  7. With NAC subscription, an expiration policy can also be configured for user managed MPSKs

Configuring User Managed MPSK

These are the steps to configure user managed MPSK with Central NAC:

  1. Create a WLAN and uncheck 6Ghz band since MPSK is not supported with WPA3
  2. Select security as Personal, Key Management as MPSK AES and Authentication > Server Group as Central NAC as shown below


Creating MPSK WLAN
Creating MPSK WLAN


  1. Once the WLAN has been created, assign it to appropriate scope. For tunneled SSIDs, ensure that the WLAN is assigned to the Device Group scope
  2. Next create an Authentication Profile from Central NAC > Configuration > Authentication Profile by selecting the Authentication Type as MPSK, the network created previously and the IDPs where user accounts are present

INFO

Both user managed and admin managed MPSK can be used over the same SSID or it can used over different SSIDs. To use user managed MPSK, select appropriate IDPs in the authentication profile. To use admin managed MPSK, create MPSK keys under the Named MPSK Store for the WLAN.



Creating MPSK Authentication Profile
Creating MPSK Authentication Profile


  1. With NAC subscription, there is an option to specify an expiration policy for the user managed MPSK keys. Without NAC subscription, MPSK key expiration is tied to the user account in IDP. When user accounts in IDP are deleted / disabled the associated MPSK keys are removed from Central NAC

  2. Select a portal customization profile if you wish to customize the MPSK onboarding page by adding background images, terms and conditions page before login etc. Portal customization profile can be created under Central NAC > Configuration > Portal Customization

  3. Once the authentication profile has been created, the MPSK self service portal would be visible within the profile and can be distributed to the users



Creating MPSK Authentication Profile
Creating MPSK Authentication Profile


INFO

The user onboarding or self service portal is accessible over the internet. So users do not have to be connected to a corporate network to generate MPSK keys

Admin Managed MPSK

Apart from user owned devices, MPSK can be used with devices that are corporate owned and managed. In these cases the devices are not assigned to a specific user but is part of the corporate assets. Here, the network admin can create a MPSK that can be used with a single device or a group of devices.

Some scenarios where admin managed MPSK can be used:

  • Connect corporate owned IoT devices
  • Provide connectivity to visitors at an event

How it works:

  1. Admin logs into HPE Aruba Networking Central and accesses the Central NAC Card
  2. Within Central NAC, admin navigates to Configuration > Identity Management > Named MPSK Store

INFO

Note the Named MPSK store only shows up only if a MPSK enabled WLAN and authentication profile has been created as described in the previous sections

  1. Add MPSK by providing a name to be associated with the MPSK and the role to be assigned to the devices that connect using this MPSK. The name has to be in UPN format like some-name@domain.example

TIP

Note that the name just needs to be in UPN format. It does not have to be a valid email nor the domain name part be a valid domain.The UPN format for the name can be used to indicate location and function of the device. Example: temperature-sensor@sanjoseHQ.solararesearch

  1. Share MPSK with whoever has access to configure the device
  2. Devices connect using the appropriate MPSK
  3. Appropriate role is assigned based on what is selected while creating the MPSK
  4. If the Named MPSK is deleted, all the devices that are connected using the MPSK will be disconnected from the network

Configuring Admin Managed MPSK

Below are the steps to configure admin managed MPSK with Central NAC:

  1. Create a WLAN and uncheck 6Ghz band since MPSK is not supported with WPA3
  2. Select security as Personal, Key Management as MPSK AES and Authentication > Server Group as Central NAC as shown below


Creating MPSK WLAN
Creating MPSK WLAN


  1. Once the WLAN has been created, assign it to appropriate scope. For tunneled SSIDs, ensure that the WLAN is assigned to the Device Group scope
  2. Next create an Authentication Profile from Central NAC > Configuration > Authentication Profile by selecting the Authentication Type as MPSK, the network created previously. IDPs are not needed for Admin managed MPSK.

INFO

Both user managed and admin managed MPSK can be used over the same SSID or it can used over different SSIDs. To use user managed MPSK, select appropriate IDPs in the authentication profile. To use admin managed MPSK, create MPSK keys under the Named MPSK Store for the WLAN.

  1. Created Named MPSK keys under **Configuration > Identity Management > Named MPSK Store for {WLAN-Name} > Add

The name should be in the format of an email like hvac-system@dallasWarehouse.ridgeview . The format can be used to convey information about the type of device and location where it is at. It can be any arbitrary name and does not have to be a valid domain name.

Assign a role that is appropriate for the device and select expiration if desired.

INFO

With admin managed MPSK / Named MPSK, the role assigned while creating the key is assigned to the device when it connects to the network. Named MPSK authentication does not hit the authorization policy rules



Creating Named MPSK
Creating Named MPSK


Frequently Asked Questions

Q: If MPSK key is renegerated what happens to devices connected using previous MPSK?
A: When MPSK key is regenerated, all devices connected using the previous MPSK is disconnected and authentication would continue to fail for those devices until they are updated with the new MPSK

Q: Does MPSK work with WPA3?
A: Current implementation of MPSK only works with WPA2. 6 Ghz band has to be disabled in WLANs where MPSK with Central NAC is to be enabled


Last modified: July 7, 2026 (ea367d26)