Glossary

SSID (Service Set Identifier)

An SSID (Service Set Identifier) is the name of a WiFi network — the label devices show when you search for available connections. It can be up to 32 characters, is broadcast by access points, and is how users and devices identify which wireless network to join.
Last updated: August 10, 2026

What an SSID is

An SSID, or Service Set Identifier, is simply the name of a WiFi network. When you open the WiFi settings on a phone or laptop and see a list of networks, each name in that list is an SSID. It can be up to 32 characters long and is set by whoever configures the access point.
The SSID is how a device knows which of the many overlapping wireless networks around it to connect to. It is a human-friendly label, not a security feature in itself.

SSID vs BSSID

The SSID is the network's name; the BSSID (Basic Service Set Identifier) is the unique MAC address of an individual access point's radio. In a large network, many access points broadcast the same SSID — say, "CompanyWiFi" — but each has its own BSSID.
This is what lets a device roam. It stays on the same named network (SSID) while moving between different physical access points (BSSIDs) as it walks through a building.

How SSIDs work

Access points advertise their SSID in beacon frames broadcast many times a second, which is how nearby devices discover available networks. A device can also send a probe request to look for a specific network it has joined before.
When a user selects a network, the device associates with the access point broadcasting that SSID. If the network is secured, it completes the authentication and encryption handshake before traffic can flow.

Multiple SSIDs and VLANs

A single access point can broadcast several SSIDs at once — for example, one for staff and one for guests. Each SSID is typically mapped to its own VLAN or segment, so the traffic on each network is kept separate even though it travels over the same hardware.
This is the standard way organizations separate guest, staff and IoT traffic without installing separate physical networks for each.

Hidden SSIDs and security

An access point can be set to not broadcast its SSID, making the network "hidden." This is sometimes presented as a security measure, but it offers little real protection. The network name is still visible in other traffic and easily discovered with basic tools.
Hiding an SSID can even cause connectivity and roaming issues. Real WiFi security comes from strong encryption and authentication such as WPA2 or WPA3, not from concealing the name.

SSID naming best practices

How an SSID is named and structured matters more than whether it is hidden:

  • Use clear, distinct names for different networks, such as separate guest and staff SSIDs.
  • Avoid embedding sensitive information like a company department or location detail.
  • Keep the number of SSIDs reasonable, since each one adds management overhead and airtime.
  • Secure every SSID with appropriate encryption rather than relying on the name.

SSIDs, roaming and WiFi design

SSID design has a direct effect on performance, not just naming. Because many access points share one SSID, the way they are configured determines how smoothly devices roam between them. Standards such as 802.11k, 802.11v and 802.11r help a device find and move to the best access point quickly. A user walking through a building keeps a strong connection on the same SSID without dropping.
Each SSID an access point broadcasts also consumes airtime with its beacon frames. A handful of SSIDs is fine; a long list wastes capacity and can actually slow the network, especially in dense environments. Good WiFi design keeps the SSID list lean and uses VLANs, roles and per-device keys to separate traffic instead of spinning up a new SSID for every group.

How many SSIDs is too many

A common pattern is just two or three SSIDs. There is one for staff secured with WPA2 or WPA3-Enterprise, one branded guest network behind a captive portal, and sometimes one for IoT using per-device keys. That covers most needs while keeping airtime efficient.
When more separation is needed, per-device keys such as PPSK let many users share a single SSID while still landing on isolated segments. That is how student housing and multi-tenant buildings give everyone a private network without broadcasting hundreds of SSIDs. The principle holds throughout: use the SSID for what users see, and use VLANs, roles and keys for how traffic is actually separated.

SSIDs with Cloud4Wi

Cloud4Wi works across the SSIDs an organization defines. Examples include a branded guest SSID with a captive portal, a staff SSID secured with WPA2 or WPA3-Enterprise, and per-device keys on a shared SSID for IoT or residents. Managing these consistently across many sites, with the right policy and segmentation on each, is exactly what a cloud platform makes practical.
In short, an SSID is the simplest-sounding part of WiFi and one of the easiest to get wrong. The name itself is just a label; the value lies in how the networks behind it are structured, secured and roamed. A small number of well-designed, well-secured SSIDs — backed by VLANs, roles and per-device keys for separation — almost always beats a long list of networks. Managing that consistently across many sites is where a cloud platform proves its worth.

— FAQ

Frequently asked questions

Everything you need to know about SSID and how it works.

The SSID is the network's name, while the BSSID is the unique MAC address of an individual access point's radio. In a large network, many access points broadcast the same SSID but each has its own BSSID. This lets a device roam: it stays on the same named network while moving between different physical access points through a building.

Not meaningfully. A hidden SSID is not broadcast in beacons, but the network name still appears in other traffic and is easily discovered with basic tools. Hiding it can also cause connectivity and roaming problems. Real WiFi security comes from strong encryption and authentication such as WPA2 or WPA3, not from concealing the network name.

Yes. A single access point can broadcast multiple SSIDs at once, such as one for staff and one for guests. Each SSID is usually mapped to its own VLAN or segment so traffic stays separate over the same hardware. This is the standard way organizations isolate guest, staff and IoT traffic without building separate physical networks for each.

Access points advertise their SSID in beacon frames broadcast many times a second, so nearby devices discover available networks. A device can also probe for a specific network it joined before. When a user selects a network, the device associates with the access point broadcasting that SSID and completes the security handshake before any traffic flows.

Use clear, distinct names for different networks, such as separate guest and staff SSIDs, and avoid embedding sensitive details like department or location. Keep the number of SSIDs reasonable, since each adds management overhead and consumes airtime. Most importantly, secure every SSID with appropriate encryption rather than relying on the name for any protection.

Ready to reimagine your WiFi?

Spin up your 30-day free trial in minutes, or book time with our team of WiFi experts to scope an enterprise rollout.

  • SOC 2 certified
  • No credit card required
  • GDPR & global compliance
  • No rip-and-replace