MAC Address Randomisation
MAC address randomisation is a privacy feature, on by default in iOS 14+ and Android 10+, that presents a random per-network hardware address to WiFi networks instead of the device's permanent factory-assigned MAC address.
MAC address randomisation is a privacy feature in modern phone and laptop operating systems that presents a random hardware address to each WiFi network, instead of the device's permanent, factory-assigned MAC address. Its purpose is to stop networks and retail sensors from tracking a device (and therefore a person) across locations using the MAC address as a persistent identifier.
How each operating system behaves
- iOS / iPadOS: since iOS 14, "Private Wi-Fi Address" is on by default. Apple's settings are Off, Fixed and Rotating. Since iOS 18, Fixed is the default on secured networks such as WPA2 or WPA3 Personal and Enterprise, and Rotating, which changes the address every two weeks, is the default for open networks, Enhanced Open (OWE) and captive portals.
- Android: since Android 10, a random per-SSID address is the default, persistent for each saved network; later versions add a non-persistent option for some networks.
- Windows 10 / 11: random hardware addresses are supported but off by default.
- While scanning: all modern devices also randomise the address in probe requests, before joining any network at all.
What it breaks, and what it does not
Randomisation largely killed passive WiFi analytics - counting probe requests to estimate footfall, or recognising the same phone across different venues - because the address changes per network and per scan. It does not break captive-portal marketing: the guest's identity comes from the sign-in itself (an email address or phone number), not the hardware address. An iPhone on a guest network with a captive portal may present a new address every two weeks and be asked to sign in again, but the email it signs in with is the same, so a returning regular is still recognised.
What venues should take from it
Build measurement on authenticated, consented first-party capture rather than passive device tracking. It is more accurate, unaffected by OS privacy changes, and compliant by design - see WiFi data capture and why anonymous foot-traffic counting is fading.
Related terms
Footfall Analytics
Footfall analytics is the measurement of how many people visit a physical location, when they visit, how long they stay, and how often they return, using sensors such as WiFi access points, cameras, or door counters.
WiFi Data Capture
WiFi data capture is the process of collecting customer information - typically name, email, mobile number or social-login identity - when a guest connects to a venue's WiFi via a captive portal.
Captive Portal
A captive portal is a web page that public WiFi users see before being granted internet access - typically used to authenticate users, accept terms, and capture data such as email or social-login identity.
Guest WiFi
Guest WiFi is a public, internet-only WiFi network a business offers to customers, separate from its private back-office network, typically secured by a captive portal that requires sign-in.
Try CaptiFi free for 30 days
Capture guest emails, run automated email/SMS campaigns, and grow Google reviews - all from your existing WiFi.