Getting a new IoT device onto a Wi-Fi network is still a surprisingly manual job. Someone has to enter a network name and password, scan a QR code or pair it through a phone app, then register it with the right cloud service. That is manageable for a smart speaker at home. It becomes expensive and risky for a company installing thousands of sensors, cameras or edge computers across dozens of sites.
The Wireless Broadband Alliance (WBA) and the FIDO Alliance say they have shown a way to remove those steps. Their newly published OpenRoaming for IoT trials report describes how devices provisioned at the factory can connect to Wi-Fi automatically when first powered on, prove their identity and hand themselves over to their rightful owner, without anyone touching a keyboard.
The approach combines three existing standards: WBA's OpenRoaming federation, the Wi-Fi Alliance's Passpoint technology, and FIDO Device Onboard (FDO).
How Zero-touch Onboarding Works
The process splits onboarding into two stages: getting a first connection, then establishing ownership.
Stage One: A Bootstrap Connection
Manufacturers load each device with credentials that are cryptographically tied to that specific unit before it leaves the factory. When the device is switched on within range of an OpenRoaming network, it uses Passpoint to authenticate automatically and join the network, much as a phone can join a participating public hotspot without a login screen.
That first connection is not meant to be permanent. Its job is to give the device just enough access to reach onboarding services safely.
Stage Two: Proving Who Owns It
Once online, FDO takes over. FDO, which the FIDO Alliance developed with industry members including Intel, Arm, Microsoft, Qualcomm and Infineon, uses a digital ownership voucher that travels through the supply chain with the device. When the device reaches its buyer, the voucher lets it confirm who its owner is and receive that owner's settings and credentials.
That design supports what the FIDO Alliance calls late binding: a company does not need to decide at the time of manufacture which cloud or management platform a device will connect to. The choice can be made at installation, which FIDO says can cut costs in deployments where manual onboarding sometimes costs more than the hardware itself.
After ownership is established, the device receives either permanent OpenRoaming credentials or the credentials for the network it will actually use, and moves across to that network.
What The Trials Showed
According to the report, the trials confirmed that factory credentials allowed devices to join OpenRoaming networks without manual Wi-Fi setup, that OpenRoaming provided a secure bootstrap link, and that FDO handled ownership transfer and configuration delivery successfully. The model also supports redeploying a device to a new owner or site.
Security firm VinCSS built the proof of concept on a Raspberry Pi running Linux, keeping its private keys in a secure hardware element, testing FDO's ownership transfer steps at first power-on. The results are an early validation, not a large-scale field deployment.
The companion framework published by the WBA sets out the architecture in more detail, with contributions from members including Intel, Cisco and Comcast.
"This work marks an important step, extending OpenRoaming further into IoT and edge device use cases," said Tiago Rodrigues, president and chief executive of the WBA.
Why The Partners Care
For network equipment makers and chip vendors, easier onboarding removes a barrier to selling more connected devices into enterprises.
"Setting up large numbers of connected devices manually is a major hurdle for businesses today," said Mark Grayson, a Cisco Fellow.
"As IoT deployments continue to scale, the industry needs a simpler and more secure way to bring devices online from first power-on," added Dr Necati Canpolat, senior staff for next generation and standards at Intel.
Why This Matters For IoT Security
Manual onboarding is not just slow. It is also a common source of security weaknesses. Shared Wi-Fi passwords get reused across sites, default credentials are left unchanged, and devices are sometimes connected to the wrong network or registered to the wrong account.
Tying identity to hardware at the factory, and verifying ownership cryptographically, reduces those risks. It also fits the direction of regulation. In Europe, the Cyber Resilience Act for IoT makers is pushing manufacturers toward secure-by-default products, including how devices are configured and authenticated out of the box.
"Enterprises no longer have to choose between speed and security," said Richard Kerslake, who works on market development for connected standards at the FIDO Alliance.
A Wi-Fi Counterpart To ESIM
The idea mirrors changes on the cellular side. There, eSIM standards such as SGP.32 let companies load and switch operator profiles remotely, so devices can be shipped without committing to a single carrier. We explored that shift in our piece on the fight over the IoT SIM. OpenRoaming with FDO aims to bring a similar level of automation and flexibility to Wi-Fi devices.
What Still Needs To Happen
The WBA and FIDO Alliance are clear that this is a starting point. They are inviting companies to join multi-vendor trials, test real deployments and work on certificate lifecycle management. They also want to address environments without internet access and devices with very limited processing power, both common in industrial IoT.
For enterprises, adoption will depend on several practical factors:
· Whether their device suppliers support FDO and ship with factory credentials.
· Whether OpenRoaming or compatible Passpoint networks are available where devices are installed.
· How ownership vouchers are handled when devices pass through distributors and integrators.
· How certificates are renewed or revoked over a device's life.
For more on how devices, gateways and networks fit together in industrial settings, see our explainer on industrial IoT connectivity.
The Bottom Line
The WBA and FIDO Alliance trials show that factory-provisioned devices can join Wi-Fi and transfer ownership securely without manual setup, using standards that already exist. For companies deploying large numbers of IoT and edge devices, that could cut installation time and close common security gaps.
The work is still at the proof-of-concept stage. Its real impact will depend on how many device makers adopt FDO, how widely OpenRoaming networks spread in enterprise sites, and how smoothly the model holds up in multi-vendor, real-world deployments.