I think it’s useful for headless devices — signing up, say, a thermostat using a guest portal is ridiculous.
WPS sort of tried to cover this use case, but WPS is a disaster.
WPS sort of tried to cover this use case, but WPS is a disaster.
My approach is just setting proper firewall rules on a dedicated ESSID with a dedicated VLAN. A device on a restricted VLAN shouldn't be able talk to anything. The downside is its more work, but the plus side is it can be done on trusted firmware (OpenWRT) and not something that would require an entire code audit to determine if there are any logic flaws.
(Also, “push the button” is a bit of an awkward concept with multiple APs.)
edit: it’s also a disaster due to a proliferation of crappy client devices that more or less require it.