Glossary

MPSK (Multi Pre-Shared Key)

Multi Pre-Shared Key (MPSK) is Aruba's method for assigning multiple unique pre-shared keys to a single SSID, each mapped to a role or device. Like PPSK and iPSK, it provides per-device keys and policy without 802.1X supplicants.
Last updated: August 10, 2026

What MPSK is

Multi Pre-Shared Key (MPSK) is Aruba's name for per-device pre-shared keys on a shared SSID. Rather than one password for the whole network, MPSK lets each device authenticate with its own key and receive its own role and policy. It brings unique-credential security to devices that cannot run an 802.1X supplicant.
MPSK is Aruba's expression of the broader PPSK concept. Cisco's equivalent is Identity PSK (iPSK), and PPSK is the generic, vendor-neutral term.

MPSK Local vs MPSK with ClearPass

Aruba offers MPSK in two forms, and the difference is where the keys and policy live. MPSK Local stores keys directly on the access point or gateway, so the matching and role assignment happen on the device itself. It is simple to deploy and works well in cloud-managed Aruba Central environments.
MPSK with ClearPass uses a RADIUS server to manage keys and return richer policy attributes, similar to how Cisco's iPSK leans on ISE. This gives more centralized control and finer policy at the cost of running ClearPass.

How MPSK works

When a device connects, the Aruba infrastructure matches the unique key the device presents during the WPA handshake. With MPSK Local, the access point checks the key against its local configuration and assigns the mapped role. With ClearPass, a MAC authentication lookup returns the device's key and policy from the RADIUS server.
Either way, each key can map to a distinct VLAN, role or access control list, so devices that share an SSID are still separated and governed individually.

Setting up MPSK

An MPSK Local setup defines the named keys and their roles directly in Aruba Central or on the controller, which suits smaller or cloud-managed deployments. An MPSK with ClearPass setup registers endpoints and key mappings in ClearPass and points the WLAN at it for MAC authentication.
The choice usually comes down to scale and policy needs. Choose Local for simplicity, or ClearPass when you want centralized control, detailed policy, and integration with the rest of an Aruba security stack.

The PPSK family

MPSK, iPSK and PPSK are the same idea under three labels. PPSK is generic, iPSK is Cisco, and MPSK is Aruba. All deliver unique per-device keys on one SSID so you can secure and segment devices that cannot run 802.1X.
Seeing them as one capability — rather than three competing technologies — makes it much easier to plan a consistent strategy across a mixed-vendor network.

Where MPSK fits

MPSK is a strong fit for IoT and BYOD on Aruba networks. It removes the shared-password risk for cameras, sensors and other headless devices, and it gives BYOD users a unique, revocable key without a certificate rollout.

  • Headless IoT devices that need segmentation but have no supplicant.
  • BYOD on Aruba where 802.1X is not yet deployed everywhere.
  • Sites that want per-device revocation without a separate SSID per group.

MPSK with Cloud4Wi

Because Cloud4Wi is vendor-agnostic, organizations running mixed Aruba and Cisco estates can apply a consistent per-device key strategy and centralize policy. This holds regardless of whether a given site uses MPSK Local, MPSK with ClearPass, or Cisco iPSK. The operational model stays the same even as the underlying mechanism changes from site to site.

MPSK and the shift away from shared keys

MPSK exists because the single shared WiFi key has become a liability in environments full of IoT and personal devices. One password for everything cannot be attributed to a device, spreads informally, and forces a disruptive re-key across the whole network when it leaks. MPSK replaces that with per-device keys that can be issued, scoped and revoked individually.
On Aruba networks this matters most for IoT. Cameras, sensors, displays and controllers can each receive their own key and role, so they sit in separate segments rather than sharing one flat trust zone. If a single device is compromised, the damage is contained to its own segment instead of exposing every other device that shared the key.
Whichever delivery model a site uses, the operational discipline is the same as for any per-device key scheme. Generate keys cleanly, map each to the right role, rotate and expire them on a schedule, and revoke immediately when a device leaves. Done well, MPSK gives an Aruba estate per-device accountability and segmentation without the supplicant and certificate overhead of full 802.1X.
For Aruba-centric organizations, MPSK is the most direct route to per-device security on existing infrastructure. It needs no supplicant, no certificate authority, and no change to how users connect beyond entering their own key.
The strategic value grows in mixed environments. When an estate spans Aruba and Cisco, it helps to treat MPSK and iPSK as one capability, managed through a single platform and a single policy model. That avoids the trap of running two parallel key systems with different tools and processes. That consistency is what keeps a per-device key strategy maintainable as the network grows and hardware is refreshed.
For organizations that have lived with a single shared key for years, MPSK is often the lowest-friction first step toward per-device security and segmentation. It also lays the groundwork for a later move to certificate-based authentication where that is warranted.

— FAQ

Frequently asked questions

Everything you need to know about MPSK and how it works.

MPSK is Aruba's branded implementation of the per-device pre-shared key concept, while PPSK is the generic term for that same concept. If you run Aruba hardware, you will use MPSK; the underlying idea is identical. Both issue a unique key per device on a single SSID and apply policy per key. Cisco's equivalent is iPSK.

MPSK Local stores and matches keys directly on the access point or gateway, which keeps the design simple and works well in cloud-managed Aruba Central setups. MPSK with ClearPass uses a RADIUS server to manage keys and return richer policy attributes, giving more centralized control and finer segmentation at the cost of running ClearPass infrastructure.

Yes. MPSK and iPSK are vendor versions of the same per-device key concept, so the policy model carries across both. A vendor-agnostic platform lets you generate, distribute and revoke keys and apply segmentation with one operational process, even though Aruba and Cisco implement the underlying mechanism differently and use different names for it.

Choose MPSK when devices cannot run an 802.1X supplicant or when certificate provisioning is not yet in place. It removes the shared-password risk for IoT and gives BYOD users a unique, revocable key with far less overhead than a full 802.1X and PKI rollout. For managed corporate laptops, 802.1X with EAP-TLS is still stronger.

Each MPSK key can map to its own VLAN, role or access control list. When a device connects with its unique key, Aruba assigns the matching policy, so two devices sharing the SSID can land in different segments with different permissions. That lets you isolate IoT, guests and staff without creating a separate SSID for each group.

Ready to reimagine your WiFi?

Spin up your 30-day free trial in minutes, or book time with our team of WiFi experts to scope an enterprise rollout.

  • SOC 2 certified
  • No credit card required
  • GDPR & global compliance
  • No rip-and-replace