Updated: October 2026
A laptop asks for a "WPA2 password", and the person holding it has no idea what that is. It's the Wi-Fi password, and the label tells you how the network is locked rather than what to type. Here's what WPA2 means, why one shared office password slowly turns into everyone's password, and when it's time to move to WPA3.
What Is a WPA2 Password?
A WPA2 password is the passphrase that unlocks a Wi-Fi network secured with WPA2-Personal, the security standard routers have used since 2004. It's the same thing as the Wi-Fi password. It has to be 8 to 63 characters long, and the router uses it to build fresh encryption keys for every device that joins.
Phones and Macs name the protocol in the prompt because the network announces it. Nothing is broken. The device is asking for the key to a WPA2 network, and that key is whatever was set on the router.
At home, it's on the sticker or in the router's settings page. At work, it's with IT, and if you have to go hunting for it, that's worth a second look. A company network that runs on one password printed on a card is the problem the rest of this post is about.
This short explainer walks through every Wi-Fi security type, from the broken ones to WPA3, in plain language.
How to Find or Change a WPA2 Password
On a Windows PC that's already connected, one command shows the saved key for a network:
codenetsh wlan show profile name="NetworkName" key=clear
Look for the Key Content line. On a Mac, open System Settings, go to Wi-Fi, find the network under known networks and choose Copy Password. On an iPhone, tap the network in Wi-Fi settings and tap the password field.
Changing it happens on the router or the access point controller, in the wireless security settings. Pick WPA2-Personal with AES, or WPA2/WPA3 mixed mode if every device supports it, and use at least 16 random characters. Then plan for the part nobody enjoys: every device that used the old password has to be told the new one.
WPA2-Personal vs WPA2-Enterprise
WPA2 comes in two flavours, and they answer different questions. Personal asks "do you know the password?" Enterprise asks "who are you?"
| WPA2-Personal (PSK) | WPA2-Enterprise (802.1X) | |
|---|---|---|
| How you join | One shared password | Your own account or a device certificate |
| Who checks you | The access point | A RADIUS server, usually tied to Entra ID or Active Directory |
| Removing one person | Change the password on the router and every device | Disable their account |
| Setup effort | Minutes | A RADIUS service, and ideally certificates pushed by MDM |
| Fits | Homes, guest networks, a handful of devices | Company-owned laptops and phones |
There's a middle ground too. Several business access point vendors can hand each person or device its own private key on the same network. It feels like a normal Wi-Fi password to the user, but one key can be revoked without touching the rest.
Why One Office Password Becomes Everyone's Password
A shared password spreads. The new hire gets it on day one. So does the contractor, the visiting auditor, and the phone of everyone who ever asked at reception. It gets written on a whiteboard, pasted into a chat, and saved on personal devices that never leave the building's range.
Then people leave, and the password stays. Changing it means re-entering it on every laptop, printer and scanner in the office, so it tends not to happen. Build Wi-Fi into your client offboarding checklist and the problem at least stops growing.
This r/networking thread starts exactly there: a small business where the internal Wi-Fi ran on "a simple password that everyone knows". The replies are a tour of how teams split company devices from personal ones.
Where WPA2 Shows Its Age
WPA2 still encrypts traffic well when it's set up with AES and a strong password. Its weak spots are in how devices agree on keys.
In 2017, researcher Mathy Vanhoef at KU Leuven published KRACK, a set of attacks that tricked devices into reusing encryption keys during the WPA2 handshake. The fix needed patches on both sides, the access points and the laptops and phones that connect to them. Devices that never got updates are still exposed.
The other weakness is offline guessing. Someone in range can capture a WPA2-Personal handshake and try passwords against it later, at their own pace, without the network ever noticing. A short password falls quickly that way, especially one from the most common passwords lists attackers start with. A long, random one holds up far better.
When to Move to WPA3
WPA3 arrived in 2018 and fixes both problems. WPA3-Personal replaces the old handshake with SAE, which stops offline guessing, and WPA3-Enterprise adds stronger cryptography for sensitive networks. The Wi-Fi Alliance now requires WPA3 support for Wi-Fi CERTIFIED devices.
New hardware is forcing the move. Cisco's 6 GHz and Wi-Fi 7 guide (July 2026) spells it out: the 6 GHz band only allows WPA3 or Enhanced Open networks, and Wi-Fi 7 requires WPA3 on 2.4, 5 and 6 GHz alike. If new access points are on the budget, WPA3 comes with them.
The bridge is transition mode, which lets WPA2 and WPA3 devices share one network name. It helps, with two catches. Some older phones, laptops and embedded devices still struggle to join, and the same Cisco guide notes transition mode isn't supported on 6 GHz or Wi-Fi 7. List what connects before you switch: printers, scanners, door controllers and meeting-room gear are the usual holdouts.
A Wi-Fi Setup That Works for a Small Office
A lot of the risk disappears when company devices and everything else stop sharing one network. A simple layout uses three.
The staff network carries company-owned laptops and phones only. It runs WPA2-Enterprise or WPA3-Enterprise, with certificates pushed by your device management tool, so nobody types a Wi-Fi password at all. Our Microsoft Intune review covers how that works for Windows fleets.
The guest network takes visitors and personal phones. It gets its own long password, rotated on a schedule, and it can reach the internet but nothing inside the office. A QR code on the wall makes rotation painless.
The devices network holds printers, TVs and anything that can't do Enterprise authentication, walled off from both. Our smart office IT requirements guide goes further on coverage and device planning.
In this r/sysadmin thread, a team going passwordless asks how staff should join Wi-Fi on personal devices. The top answer is short: device certificates for company gear, and personal devices on the guest network.
One Password Is a Starting Point
A WPA2 password is just the Wi-Fi password, and for a home network that's enough. For an office, one shared key is a list of everyone who ever worked there. Split company devices onto Enterprise authentication, give guests their own network, and plan WPA3 into the next access point refresh.
When someone leaves, the Wi-Fi is one line on a longer list. The client offboarding checklist is the next read.
Content Marketing Lead
Ohayo! I run content, SEO, social, and community at Flamingo. Before IT, I worked as a correspondent for Ukraine's Public Broadcasting Company and have a Master's in journalism.
