Services · PenwinIn

PenwinIn: Wi-Fi authentication for schools and colleges

A school's Wi-Fi password stops being secret on day one: it passes from one student to another, gets out of the building, and the only answer is to change it and reconfigure every device. PenwinIn replaces it with the account each person already has at the school: students, teachers and administrative staff sign in with their email address and password, the same ones they use for Google Workspace or Microsoft 365. The school knows who is connecting, when and from where, applies the appropriate rules to each profile and cuts off access for one specific person without affecting anyone else. PenwinEdu runs the complex part – the authentication server – as a service for publicly funded private schools (concertados), private schools, universities, business schools and vocational training centres: joiners and leavers come through automatically from the directory, and the school year is kept running with 24/7 monitoring and technical support that responds within 4 working hours.

Email us at info@penwin.org and we'll explain how to move your school's Wi-Fi from a shared password to each user's own account with PenwinIn. The initial assessment and proposal are free and come with no obligation.

Everyone signs in with their own account, not the school's password

With a shared password (WPA2-Personal), every device presents itself to the network with the same credential: the school cannot tell who was connected or at what time, cannot apply different policies to a pupil in the 2nd year of ESO (compulsory secondary education) and to a member of the senior leadership team, and cannot cut off access for a single device without changing the password for the whole school. We cover on our blog why that is a security problem and not just the September hassle.

PenwinIn replaces that password with each user's identity over WPA2/WPA3-Enterprise with 802.1X: whoever connects identifies themselves with their school email address and password, and the network checks with the authentication server before letting them in. There is a fundamental difference from the shared password, and it is not a technical one. The Wi-Fi password cost nobody anything: reading it out in the playground was free. A personal password can be lent too, but lending it means handing over your whole school account – email, documents, marks – and nobody does that lightly.

The part that holds a school back – setting up, securing and maintaining a RADIUS server with its backups and updates – is precisely the part PenwinEdu runs as a service. The school manages users, profiles and devices from the dashboard at https://auth.penwin.cloud (in Spanish), with 24/7 monitoring of the platform.

  • 802.1X plus RADIUS: the network checks with an authentication server before admitting each device.
  • Each user signs in with their school email address and password, not with a shared secret.
  • Access is cut off for one specific person without changing the password for the whole school.
  • Per-session encryption, not a single secret shared by the whole school.

Joiners and leavers handled automatically from the school directory

PenwinIn syncs with the directory the school already uses: Google Workspace or Microsoft 365. The practical consequence is that the network no longer has its own list of users that someone has to maintain by hand. When the school office enrols a student and their account is created, that student can authenticate on the Wi-Fi; when they leave and their account is deactivated, they can no longer get onto the school network and are left with just the guest network, with internet access and no access to internal resources. That does away with setting up whole year groups in September and, above all, with the access that nobody removes in June because nobody has it on record; the same applies to a teacher who joins mid-year or to two weeks of cover.

  • Sync with Google Workspace and Microsoft 365.
  • When a student or teacher joins or leaves, their network access follows automatically.
  • No parallel user lists to maintain year after year.

Segmentation by role: students, teachers, staff and guests

Because the network knows who is connecting, it can treat each profile differently. PenwinIn segments users into students, teachers, staff and guests, and that classification is applied at the moment of connection, regardless of the access point or building: classroom traffic is kept separate from management and administration traffic, student devices cannot reach internal resources such as servers, school office printers or cameras, and a visitor gets nothing but internet access. And because the profile travels with the user, a teacher keeps their access level when they move to another classroom or block, without multiplying networks with different passwords.

  • Separate profiles for students, teachers, administrative staff and visitors.
  • Academic traffic kept separate from the school's management traffic.
  • The access level follows the user around the school; it does not depend on which SSID they connect to.

Traceability: who connected, when and from where

PenwinIn logs every authentication in real time and keeps an auditable history: which identity, which device, at what time and through which access point, including rejected attempts. With a shared password that information simply does not exist, because every device presents itself in the same way; when each person signs in with their own account, the connection is tied to a specific person. It helps to piece together what happened after a behaviour or security incident, to show that the school network is under control and, day to day, to turn ‘the Wi-Fi isn't working’ into a diagnosis.

  • Real-time logs of accepted and rejected authentications.
  • History searchable by user and by device.
  • Faster diagnosis of everyday connectivity issues.

It builds on the network the school already has

PenwinIn is deployed on the access points the school already has, provided they support WPA2/WPA3-Enterprise and 802.1X: PenwinEdu routinely works with Ubiquiti, Cisco, Meraki, Aruba and TP-Link. The move from a shared password to per-user authentication is made on that same network hardware: the relevant SSID is published and authentication is pointed at the service. The band on which each SSID is published and its security mode are set in the deployment design, along with the coverage and access point density of each building.

  • Deployed on Ubiquiti, Cisco, Meraki, Aruba and TP-Link access points that support 802.1X.
  • On 6 GHz it broadcasts in WPA3-Enterprise with PMF, the security mode the standard reserves for that band.
  • Makes use of existing network hardware: the change is made in the SSID configuration.
  • Free, no-obligation assessment of the existing installation, and a proposal.

Why PenwinEdu

Behind the product is a team that specialises in education (concertado schools, private schools, universities, business schools and vocational training centres) and has spent more than twelve years managing the technology infrastructure of schools and colleges across Spain. Today that team manages more than 300,000 daily connections, 600 TB of internet traffic and more than 1,200 switches and firewalls. Education is our home ground: the school calendar, the connection peaks when lessons change and a whole class downloading the same content at once are all part of the working context.

The service is rounded off with 24/7 monitoring and a technical support response within 4 working hours, from our offices in Sant Cugat del Vallès, Madrid and Jaén. Work that requires taking the network down is scheduled for non-teaching periods, so the school year is not interrupted.

Frequently asked questions

What happens when a student leaves the school?

When a student leaves and their account is deactivated in Google Workspace or Microsoft 365, PenwinIn automatically stops admitting them to the school network: they are left with the guest network, with internet access and no access to internal resources. Everyone else at the school stays connected without anything being touched, because each person signs in with their own credentials and there is no common password to change.

Do the access points need replacing to use PenwinIn?

PenwinIn is deployed on the access points the school already has, provided they support WPA2/WPA3-Enterprise and 802.1X, the standard implemented by professional equipment from Ubiquiti, Cisco, Meraki, Aruba or TP-Link. The change is made in the configuration: an SSID is published that authenticates against the service instead of using a shared password. In the 6 GHz band the standard restricts security to WPA3 – Personal, or Enterprise with 802.1X – and to Enhanced Open/OWE, with PMF mandatory, so there PenwinIn broadcasts in WPA3-Enterprise; the band and mode of each SSID are set in the deployment design. PenwinEdu reviews the existing installation beforehand and builds the proposal from it.

Does it work with Chromebooks and iPads?

Yes. WPA2/WPA3-Enterprise with 802.1X is a standard supported by ChromeOS, iPadOS, iOS, Android, Windows, macOS and Linux, so a school's usual device fleet (Chromebook trolleys, classroom iPads, teachers' laptops and mobiles) authenticates without any problem. On devices managed by the school, the network profile is distributed from the management console itself, so users just have to sign in with their account the first time.

What happens if a device is lost or stolen?

Access is tied to the person's account, not to the device: their password is changed or the account is suspended in the directory, and the lost device can no longer get onto the school network. That is the main difference from a shared Wi-Fi password, where the only way to shut off access is to change the password for the whole school and reconfigure every other device. Here the incident is confined to a single account and nobody else notices.

Can visitors be given Wi-Fi?

Yes. PenwinIn includes a guest profile separate from the student, teacher and staff profiles, so a visitor, a family at a meeting or a contractor can have internet access without reaching the school's internal resources: servers, school office printers, cameras or management equipment. Guest access is logged just like the rest, so there is still a record of who has used the network.

What records are kept of connections?

PenwinIn logs authentications in real time: which identity and which device connect, at what time and through which access point, including rejected attempts. That history can be searched and makes it possible to audit network use, piece together what happened after a behaviour or security issue and diagnose specific connectivity faults, rather than relying on what each user remembers.

Does the school need to set up its own RADIUS server?

There is no need: PenwinEdu runs the RADIUS server as a service. Installation, security updates, backups and 24/7 monitoring are part of the contract, with a technical support response within 4 working hours. The school's IT team keeps the part that matters to it: managing users, profiles and devices from the dashboard at https://auth.penwin.cloud (in Spanish), with the connection trail close at hand.

What kind of institutions is PenwinIn designed for?

PenwinEdu specialises in education: publicly funded private schools (concertados), private schools, universities, business schools and vocational training centres. It has spent over a decade managing the technology infrastructure of schools and colleges across Spain. Today the company manages more than 300,000 daily connections and more than 1,200 switches and firewalls. That track record shows in how PenwinIn is deployed: work that requires taking the network down is scheduled for non-teaching periods, bulk user set-up is prepared before the start of the school year, the platform is monitored 24/7 and technical support responds within 4 working hours.

Let's talk about your school

Email us at info@penwin.org with details of your school, or fill in the contact form, and we'll reply with a specific proposal.