Think about the person who left your company last spring. Their phone almost certainly still knows your office Wi-Fi password. So does the contractor who helped with the move, the visitor who asked for it in a meeting, and every personal device that has ever been in the building.
For most small and mid-sized organizations, Wi-Fi security means one password shared by everyone. It’s simple, and that’s why it’s everywhere. But it hides a number of risks that rarely show up until something goes wrong, or until an auditor starts asking questions.
How shared-password Wi-Fi works
Most office networks use WPA2-Personal or WPA3-Personal. Both work the same way at the level that matters here: there is one secret, the Wi-Fi password (technically a pre-shared key, or PSK). Anyone who knows it can connect.
The network doesn’t know who you are, only that you know the password. That one design choice is the root of every risk below. First, it makes access hard to control. Second, the consequences are serious once the wrong person is in.
Risk 1: You can’t take access away from one person
When someone leaves, you disable their user account, collect their laptop and remove them from Microsoft 365. But you can’t remove their Wi-Fi access, because their access is the shared password.
The only fix is changing the password, which means reconfiguring every laptop, phone, printer and meeting-room device in the organization. In practice almost nobody does it, so the password stays the same for years.
Risk 2: The password spreads
A shared password never stays where you put it. Over time, it typically ends up:
with visitors and contractors who “just needed to get online”
on employees’ personal phones and tablets, which may sync it to other devices
on a sticky note, a whiteboard or a shared document
with former employees, as described above
Each of these is a device or person on your internal network that you didn’t plan for.
Risk 3: You can’t see who’s on the network
Your access points can show you a list of connected devices, but not who they belong to. Modern phones and laptops also randomize their hardware (MAC) addresses, so even the device list is hard to interpret.
If something suspicious happens on the network, the question “whose device was that?” usually has no answer.
Risk 4: The password can be guessed offline
With WPA2-Personal, an attacker within radio range, for example in the parking lot or the office next door, can record part of the connection process and then try to guess the password on their own computer. They can try enormous numbers of guesses without your network ever noticing. Short or predictable passwords, such as the company name plus the year, don’t hold up long.
There’s a second, less known issue. Someone who already knows the password and records a colleague’s connection can, under WPA2-Personal, decrypt that colleague’s traffic.
WPA3-Personal fixes both of these. Its handshake (SAE) prevents offline guessing and protects each connection individually. That’s a real improvement, and worth turning on. But WPA3-Personal is still one shared password, so risks 1, 2 and 3 remain exactly the same.
What someone can do once they’re on your network
So far we’ve looked at how Wi-Fi access slips out of your control. The more important question is what happens when the wrong person, or the wrong device, is connected. Joining your Wi-Fi puts them inside your network: next to your laptops, printers and file servers, and past the firewall that protects you from the internet.
Intercept and manipulate traffic
Anyone on the same network can place themselves between other users and the internet, for example by pretending to be the router. From there they can:
read traffic that isn’t encrypted. Typical examples are older internal systems, admin pages on printers and network devices, and some file-sharing and management protocols.
see which sites and services people use, from their DNS lookups
redirect people to fake sign-in pages that look exactly like the real ones
HTTPS protects most web traffic today, but rarely everything that runs on an internal network.
Impersonate your network
The password is the only thing that proves your network is genuine. So anyone who knows it can set up a fake access point with the same name and password. This works with WPA2-Personal and WPA3-Personal alike. Devices connect to it automatically, and all their traffic then passes through the attacker. Nothing on the user’s screen looks any different.
Attack printers, NAS and other devices
Many devices on an office network were never designed to face strangers:
NAS and file shares often hold an organization’s most valuable data, and are a favorite ransomware target.
Printers and multifunction devices often run outdated firmware with default admin passwords. Some keep copies of scanned and printed documents.
Cameras, meeting-room screens, smart TVs and building controls are rarely patched. They make good hiding places for an attacker.
The network equipment itself, such as routers, switches and access points with web-based admin pages.
Spread further and stay hidden
An intruder rarely stops at the first device. Network access is a common first step in ransomware attacks: find a weak system, take it over, and move on to servers and backups. A small device that knows the Wi-Fi password can keep that access open long after the attacker has left. It could be hidden in a cupboard, or sitting in a car outside.
Use your internet connection
Anything an intruder does online appears to come from your organization. That can mean abuse complaints, your public IP address ending up on blocklists, or questions you’d rather not have to answer.
A flat network makes all of this worse
With one password, every device usually lands on the same network segment: company laptops, personal phones, printers, smart TVs and sometimes guests. A single compromised device can then reach everything else.
Splitting devices into separate networks (VLANs) helps, but it’s hard to do reliably when the network can’t tell devices apart.
Why this matters more now
Security requirements are moving from “do you have a password?” to “can you show who has access?” Frameworks such as NIS2 and ISO 27001, and cyber-insurance questionnaires, increasingly ask organizations to control and document access to their systems. The internal network is one of those systems.
A shared Wi-Fi password makes those questions hard to answer honestly.
The alternative: an identity for every user or device
The fix is to stop asking “do you know the password?” and start asking “who are you?”. That’s what WPA2/WPA3-Enterprise does, using a standard called 802.1X. Each user or device proves its own identity, usually with a certificate, and a RADIUS server decides whether to let it in.
| Shared password (Personal) | Individual identity (Enterprise / 802.1X) |
|---|---|---|
Remove one person’s access | Change password everywhere | Disable that user or device |
Know who is connected | No | Yes, per user/device |
Fake copies of your network | Anyone with the password can create one | Devices verify the network’s certificate before connecting |
Password can leak or spread | Yes | Nothing shared to leak |
Put devices on different networks | Hard | Automatic, based on identity |
Works with existing access points | Yes | Yes. Almost all business-grade access points support 802.1X |
“Isn’t that only for large enterprises?”
It used to be. Running 802.1X traditionally meant operating your own RADIUS servers, a certificate authority and the infrastructure around them. Those are servers that need patching, backups and someone who understands them. For a small IT team, that was often reason enough to stay with the shared password.
That’s no longer true. RADIUS and certificate management are now available as cloud services. They work with your existing access points and with Microsoft Intune for getting certificates onto devices.
What this means for you
Ask yourself five questions:
When did we last change the Wi-Fi password, and how many people have left since?
If an unknown device showed up on the network today, could we find out whose it is?
If an outsider joined our Wi-Fi today, what could they reach: file shares, NAS, printers, servers?
Are guests, personal devices and company laptops on the same network?
If an auditor asked who has access to our internal network, what would we answer?
If the answers make you uncomfortable, you’re in good company. Most organizations are in the same position. The good news is that moving to individual identities is much less work than it used to be.
How we solve this: EasyRadius is a cloud RADIUS service for 802.1X Wi-Fi. It needs no servers, assigns VLANs dynamically and shows live authentication logs, so you always know who is connected. Combined with certificates from your Intune environment, it replaces the shared password with a proper identity for every device.
Ready to set it up? See the EasyRadius documentation.
Ready to set it up?
Step-by-step guide on docs.just-software.com →
Products in this article
JS
Just Software
The Just Software team
We build cloud services that make secure IT simple: certificates, RADIUS, Azure governance and more, with no servers for you to run.
Share this article:


