Coffee chat: the band that won’t accept “we’ll migrate later”
I still remember the last big campus Wi-Fi refresh I owned as an IT manager. New APs, new controllers, a carefully staged SSID cutover, and a guest network that somehow still used the same password that had been written on a whiteboard in Facilities for three years.
We survived that one with transition modes, dual SSIDs, and a lot of after-hours testing. What we didn’t have then was a band that simply refused WPA2.
That’s 6 GHz. And if you’re moving into Wi-Fi 6E or Wi-Fi 7 without treating WPA3 as a first-class workstream, you’re buying radios that will never show their real value.
What actually changed
The Wi-Fi Alliance didn’t treat WPA3 as a nice-to-have for the new spectrum. For 6 GHz operation, WPA3 is mandatory. WPA2 is not permitted. Protected Management Frames are required. Open (unencrypted) is out. For open-style access, you move to Enhanced Open / OWE, not “no password and no crypto.”
Cisco Meraki’s WPA3 Encryption and Configuration Guide lays this out cleanly: Wi-Fi 6E devices on 6 GHz must run WPA3 (Personal with SAE/H2E, Enterprise with 802.1X, or OWE for open-style use). WPA2 stays off that band.
WWT’s WPA3 primer makes the operational point just as bluntly: if you intend to operate in 6 GHz, you must operate WPA3. Legacy security configs hit a wall on new hardware and new spectrum.
Wi-Fi 7 tightens the story further. Full 802.11be features and proper Multi-Link Operation expect modern security: WPA3, stronger ciphers in many profiles, mandatory PMF, and beacon protection. Redway Networks’ Wi-Fi 7 security breakdown is a good field-oriented read: leave an SSID on WPA2 or plain open and you often don’t get a true Wi-Fi 7 connection—you drop back.
For the standards-side overview, the Wi-Fi Alliance’s security page is still the clean public summary of WPA3 and Enhanced Open.
Why this hurts real enterprise migrations
If you’ve ever run a multi-building Wi-Fi migration, you already know the client inventory is a fiction.
You’ll have:
- Corporate laptops that are fine on WPA3-Enterprise
- BYOD phones that mostly work
- Shared conference-room devices that “just need the guest password”
- Scanners, badge printers, and medical or warehouse gear that last spoke 802.11n and will never get a firmware budget
- A guest SSID that marketing still thinks of as “open Wi-Fi”
On 2.4/5 GHz, transition mode (WPA2+WPA3) is the usual bridge. Keep the SSID name, let modern clients use WPA3, let holdouts use WPA2, plan the kill date.
On 6 GHz, that bridge doesn’t carry WPA2 traffic. Transition designs typically mean:
- WPA2-capable clients stay on 2.4/5
- WPA3-capable clients can use 6 GHz
- Anything that can’t do WPA3 never sees the new band
So the business risk isn’t “security theory.” It’s capacity planning. If half your dense areas still depend on WPA2 clients, your 6 GHz airtime stays quiet while 5 GHz stays noisy. Leadership bought Wi-Fi 7 for relief. Security posture is now the throttle.
Patterns that actually work
1. Don’t treat the AP refresh as the security project. Hardware first, WPA3 later is how you end up with Wi-Fi 7 APs advertising 6 GHz and almost no one using it. Start with client capability surveys, SSID inventory, and a written exception list.
2. Split the problem by SSID purpose.
- Corporate 802.1X → WPA3-Enterprise (or transition on 2.4/5 while 6 GHz is WPA3-only in practice)
- PSK IoT / shared devices → WPA3-Personal where possible; otherwise keep them off 6 GHz and off the corporate SSID
- Guest → stop pure open; plan OWE / Enhanced Open for modern bands
- High-security / regulated → evaluate 192-bit / GCMP-256 suites early (more on that in the next topic)
Meraki’s guide has a useful migration snapshot: open guest → OWE; RADIUS corporate → WPA3 or WPA3 transition; PSK IoT/guest → WPA3 or transition; Suite B / 192-bit stays 192-bit.
3. Expect deauth drama during cutovers. Anyone who’s supported enterprise Wi-Fi has chased “random disconnects” that were management-frame abuse, sticky clients, or a bad roam. PMF being mandatory under WPA3/6 GHz is a real improvement, but only if clients support it and your monitoring can tell the difference between a PMF failure and a coverage hole. Packet captures still win arguments.
4. Validate beacons, not just the GUI. I’ve lost count of how many times a dashboard said “WPA3” while a beacon still told a messier story. If you’re enabling Wi-Fi 7, confirm AKMs and ciphers in the air. Redway’s piece is worth reading just for the “I captured tens of thousands of BSSIDs and almost none met full Wi-Fi 7 security” reality check.
5. Mind SSID grouping on modern platforms. Some vendors group SSIDs for 6 GHz / Wi-Fi 7 advertising (MBSSID groups). One non-compliant SSID in a group can pull the group’s capability down. That’s not a security footnote—that’s an ops landmine during a “quick guest SSID change.”
CISSP angle without the textbook voice
For security architecture and network security domains, this is a clean example of control dependency on technology generation. You can’t claim “defence in depth for wireless” while the new spectrum is gated by authentication/encryption modes your asset inventory can’t meet.
It also forces asset management and risk acceptance into the open. Every WPA2 holdout on the corporate SSID is either:
- migrating,
- isolated to legacy bands/SSIDs/VLANs, or
- formally accepted with a date and owner.
“We’ll leave transition mode forever” is not a control. It’s deferred technical debt with a larger attack surface (WWT is clear that transition mode keeps legacy WPA2 weaknesses in play and should not be permanent).
Practical checklist before you light up 6 GHz
- Inventory clients by WPA3 / PMF capability, not just “Wi-Fi 6 sticker on the box”
- Map each SSID to a target mode: WPA3-Enterprise, WPA3-Personal, OWE, or time-boxed transition
- Decide which SSIDs are allowed on 6 GHz at all
- Test RADIUS / EAP paths with PMF required (broken cert chains show up differently when clients can’t fall back)
- Pilot one building, watch roam failures and sticky clients, then expand
- Update guest and IoT runbooks so the service desk doesn’t “fix” every failure by recreating a WPA2 SSID
Actionable takeaway
Wi-Fi 7 and 6 GHz didn’t just add channels and marketing slides. They made modern security a condition of using the new air. WPA3 is mandatory on 6 GHz; WPA2 is banned there. If your migration plan still treats encryption mode as a post-go-live tidy-up, the spectrum you paid for will sit idle while you debug the same old 5 GHz congestion—with nicer access points.
Next up: why GCMP-256 and 192-bit WPA3-Enterprise matter when “WPA3” alone isn’t the whole story.