Rogue Access Point
A rogue access point is a wireless device connected to an organization's network without approval from IT or security teams. Because it was not authorized or configured under normal controls, it can create an unmonitored way onto the network. A common example is an 'evil twin,' a device that impersonates a legitimate access point to trick users into connecting to it.
A rogue access point is any wireless access point attached to a network without explicit authorization from network administrators, bypassing the organization's approved provisioning and security controls. It may be installed inadvertently by employees or deliberately by an attacker, and it expands the wireless attack surface by providing an unsanctioned entry path into an otherwise secured network. A frequently cited variant is the evil twin, a device that impersonates a legitimate access point to induce clients to associate with it. Detection typically relies on wireless scanning, access point inventory reconciliation, and monitoring; identifying rogue devices depends on maintaining an accurate authorized-device baseline, and detection controls carry false-positive and false-negative trade-offs.
Why it matters
A rogue access point undermines the security controls an organization relies on because it creates an unmonitored path onto a network that was otherwise provisioned and secured under defined controls. Whether installed inadvertently by an employee seeking convenience or deliberately by an attacker, the device bypasses approved provisioning and expands the wireless attack surface. Because it sits outside normal monitoring, traffic passing through it may not be subject to the logging, segmentation, or access controls applied to sanctioned infrastructure.
For environments that handle cardholder data, an unauthorized wireless entry point is a particular concern because it can provide access to systems that store, process, or transmit that data without the compensating controls assumed by the organization's security architecture. The evil twin variant compounds the risk by impersonating a legitimate access point to induce clients to associate with it, which can enable interception of the traffic those clients send. Note that the exact impact of any given rogue device depends on its placement, the network segmentation in effect, and the data reachable from that segment.
Detecting rogue access points is not trivial and depends on maintaining an accurate baseline of authorized devices. Detection controls carry false-positive and false-negative trade-offs: a legitimate but newly provisioned device may be flagged, while a carefully configured rogue device may evade scans. This means rogue access point management is an ongoing operational discipline rather than a one-time configuration, and no single scan should be treated as a guarantee that a network is free of unauthorized wireless devices.
Who it's relevant to
Inside Rogue AP
Common questions
Answers to the questions practitioners most commonly ask about Rogue AP.