Author(s): Team Cloudi-Fi
Published: August 4, 2026 Last Updated: August 4, 2026 Reading Time: 5 min
Overview
As part of a large-scale digital transformation initiative, a leading banking group set out to modernize the in-branch digital experience for clients and prospects across thousands of branches nationwide.
Problem
The banking group faced several critical challenges:
- Delivering a fast, secure, and intuitive guest Wi-Fi experience across thousands of branches while meeting strict internal security policies and regulatory requirements
- Scaling a solution across locations with different technical constraints
- Supporting tailored authentication journeys for clients, prospects, and contractors
- Maintaining reliable visitor authentication even in branches with limited mobile network coverage
Solution: How Cloudi-Fi Fits
Cloudi-Fi provided a centralized guest access platform that delivered consistent authentication, identity management, and policy enforcement across every branch.
Key Components
Identity Provider Integration
- Cloudi-Fi acted as the Identity Provider, integrating with Zscaler ZIA through SAML to authenticate guest users
- Securely routed traffic through the bank's existing security infrastructure
- Ensured policy-compliant access with full visibility into guest activity
Centralized DHCP Management
- Replaced on-site DHCP servers with a centralized, cloud-managed DHCP service
- Branches connected securely through IPsec tunnels
- Provided consistent IP address management while reducing local infrastructure requirements
Customized Authentication Journeys
- Developed more than 40 customized captive portals tailored to different visitor journeys
- Supported distinct authentication flows for clients, prospects, and contractors
- Maintained consistent brand experience across all portals
Outcomes
✓ Modernized guest Wi-Fi across thousands of branches in France with minimal operational disruption
✓ Personalized authentication journeys for clients, prospects, and contractors through more than 40 branded captive portals
✓ Centralized identity, authentication, and DHCP management, reducing operational complexity for branch IT teams
✓ Secure guest access enforced through native integration with Zscaler ZIA and existing security policies
✓ Simplified deployment by leveraging the bank's existing infrastructure without requiring major network changes
Key Features Leveraged
- Cloud Captive Portal – Secure, customizable guest access entry point
- Guest Wi-Fi Management – Centralized control across branch network
- Cloud DHCP – Scalable IP address management
- Zero Trust Security – Policy-driven access enforcement
- Zscaler ZIA Integration – Seamless security infrastructure alignment





