Guides

How to share a Wi-Fi password securely in a small office

Keep the staff Wi-Fi password off whiteboards, run a guest network that's really separate, and handle printer PINs and door, alarm and safe codes properly.

On this page
  1. Two networks, not one
  2. Keep staff from needing the staff password
  3. Guest Wi-Fi: rotate it and put it on the wall
  4. Device passwords and admin PINs
  5. Door, alarm and safe codes
  6. Shared kiosks and front-desk devices
  7. Who knows what, and when to change it

To share a Wi-Fi password securely in a small office, stop sharing the staff one. Put company laptops and phones on the staff network with a profile pushed from your device management tool, so nobody needs to be told the password, and give everyone else a guest network that can’t see anything on the office network and whose password you change regularly. Then the only Wi-Fi password anyone reads aloud is one that doesn’t matter.

The same idea applies to the other codes every office collects: the printer’s admin PIN, the router login, the door keypad, the alarm, the safe. Give each person their own code where the device allows it, keep the rest in your password manager with a named owner, and change them when someone who knew them leaves.

Two networks, not one

Most small-office Wi-Fi problems come from one network doing two jobs. Visitors, staff phones, the meeting-room TV and the finance laptop all sit together, and the password has been on the kitchen whiteboard for three years.

The staff network is for devices you manage. Use WPA3-Personal if every device supports it, or WPA2/WPA3 transition mode if a few older ones don’t, with a long random passphrase from your password manager. WPA3’s handshake (SAE) resists the offline guessing attack that lets someone who captures a WPA2 handshake try passwords at leisure, but a long passphrase is still the real protection for WPA2 devices. Turn WPS off.

The guest network is for everything else: visitors, personal phones, the smart speaker someone brought in. Most business routers and access points (UniFi, Meraki, DrayTek, TP-Link Omada) have a guest option that does the important part:

  • A separate network name (SSID), so nobody joins the wrong one by accident.
  • Isolation from the office network, so a guest can reach the internet but not your NAS, printers or file server. Test this: join the guest network and try to open the printer’s web page.
  • Client isolation, so guests can’t see each other’s devices.
  • A bandwidth limit, so one visitor’s download doesn’t stall a video call.

Keep staff from needing the staff password

If your laptops and phones are enrolled in Intune, Jamf or another device management tool, push the staff Wi-Fi as a configuration profile. New devices connect on their own, and staff never have to be told the password.

It isn’t invisible: anyone with admin rights on a laptop can read a saved Wi-Fi key back out. But it stops being something people write down, text to each other or teach to their family. And when someone leaves, you can judge whether they ever actually saw it, instead of assuming they did.

If you can afford the setup, WPA2/WPA3-Enterprise (802.1X) gives every person or device their own credentials, so a leaver’s access ends when their account does. For most offices under fifty people, a pushed profile with a strong passphrase is the realistic answer.

Guest Wi-Fi: rotate it and put it on the wall

The guest password is meant to be shared, so share it easily and change it often.

  • Rotate it monthly, and after any event where it was given to a crowd. Put a recurring task on someone’s list; nobody remembers otherwise.

  • Print it as a QR code for reception and meeting rooms. Phones join by pointing the camera at it. The format is plain text:

    qrencode -o guest-wifi.png 'WIFI:T:WPA;S:Example-Guest;P:river-cobalt-ladder-spoon;;'

    Escape any ;, ,, : or \ in the name or password with a backslash. Reprint when you rotate.

  • Send it ahead to visitors if you like. A one-time link isn’t necessary for a password that’s on the wall, though for an event you might set one link with as many views as attendees and a one-day expiry, as in the scenario table in choosing a link expiry.

A QR code on the wall is the password on the wall. That’s fine for a guest network that’s properly isolated and rotated. It is never fine for the staff network.

When a captive portal is worth it

Captive portals, the sign-in page that appears when you join, make sense when lots of different people use the Wi-Fi: a clinic waiting room, a co-working space, a shop. Voucher codes (UniFi and Omada both offer them) give each visitor a code that works for a set time, so there’s no shared password to rotate. If the portal collects names or email addresses, that’s personal data under UK GDPR: say why you collect it, keep it only as long as you need, and don’t make marketing consent a condition of getting online.

For a ten-person office with a few visitors a week, a portal is more to maintain than it’s worth.

Device passwords and admin PINs

Every office has a handful of devices with their own admin login: the router, the printer, the NAS, the CCTV recorder, the phone system, the meeting-room screen.

  • Change every default password on the day you install the device. Some printers and routers ship with the serial number or admin as the password; it’s the first thing anyone on your network will try. In the UK, the Product Security and Telecommunications Infrastructure regime has banned universal default passwords on consumer connectable products since April 2024, but older kit and business-only devices may still have them.
  • Keep them in a shared vault in your password manager, one item per device, with the device’s IP address and who looks after it in the notes.
  • Turn off remote management on the router unless you use it, and never reuse the Wi-Fi password as the router’s admin password.

Door, alarm and safe codes

Physical codes get shared more casually than any password, and outlive more staff.

Alarms. Most intruder alarm panels support a separate user code per person. Use them. A leaver then means deleting one code instead of telling everyone a new one, and the panel’s log shows whose code set or unset the alarm. Ask your installer to confirm the engineer code has been changed from its default. If you have a monitored alarm, the password the monitoring centre asks for when it calls a keyholder is a credential too; keep it in the vault and change it when a keyholder leaves.

Door keypads. Change the code when anyone who knew it leaves, and periodically anyway: worn buttons give away which digits are in the code. If staff turnover is high, fobs or a smart lock with individual or time-limited codes will save you a lot of reprogramming.

Safes. Few people should know the combination. Record who does, keep it in the vault or in a sealed envelope held elsewhere, and change it when one of them leaves.

To give a new keyholder an alarm code, tell them in person or send it as a one-time link with a short expiry. How to send a password securely has the steps. Don’t put it in the team chat with “for anyone who’s opening up tomorrow”.

Shared kiosks and front-desk devices

The reception iPad, the warehouse PC, the shop till: devices several people use, often with the password on a sticky note on the bezel.

Lock them down rather than sharing a login. Windows has a kiosk mode (Assigned Access) that runs one app under a restricted account, and Intune can configure it. iPads can be held in one app with Guided Access, or with Single App Mode on a supervised device. Android has a similar kiosk mode through managed Google Play. The device then signs in by itself to an account that can do one thing, and there’s nothing worth writing on a sticky note.

Where people do need to sign in, give each of them their own account or PIN on the device.

Who knows what, and when to change it

CredentialWho should know itWhere it livesChange it when
Staff Wi-FiNobody, ideally; the IT ownerDevice management profile, password managerSomeone who saw it leaves, or it’s been written down
Guest Wi-FiAnyone in the buildingReception, QR codesMonthly, and after events
Router, printer, NAS, CCTV adminWhoever maintains the devicePassword manager, one item eachOn installation, and when that person leaves
Alarm user codesEach keyholder, their ownThe alarm panelDelete the person’s code when they leave
Monitoring centre passwordKeyholdersPassword managerA keyholder leaves
Door keypadStaffPassword managerAnyone leaves, and every few months
Safe combinationTwo or three named peoplePassword manager or sealed envelopeOne of them leaves

When someone does leave, the physical and network codes come last in the rotation order, after the accounts that control other access. The offboarding rotation checklist puts them in context.

Send the next one as a link that expires.

ShareShield turns a password, key or file into a link that opens once and is then deleted. You can send a text secret without an account.

All guides