1.5 vCenter Topology: SSO Domains & Enhanced Linked Mode

Key Takeaways

  • Every vCenter Server 8.0 appliance embeds its own authentication services (SSO, VMCA, Lookup Service, and VMware Directory Service); the external Platform Services Controller no longer exists.

  • During Stage 2 of deployment, the first vCenter creates a new vCenter Single Sign-On domain and later vCenters join that existing domain to form Enhanced Linked Mode.

  • vCenter Enhanced Linked Mode joins up to 15 vCenter Server appliances in a single vSphere SSO domain, so one login shows and searches every linked inventory.

  • A vCenter can be moved to another SSO domain with cmsso-util domain-repoint, and a node is removed from a domain with cmsso-util unregister.

  • Broadcom recommends powered-off snapshots of all linked vCenter appliances, taken together, before risky changes in an Enhanced Linked Mode group.

Last updated: September 2026

1.5 vCenter Topology: SSO Domains & Enhanced Linked Mode

Objective 1.2 asks you to describe the components and topology of a vCenter architecture, and objectives 4.1.1 and 4.1.2 ask you to configure a new Single Sign-On domain and join an existing one. They are all the same design decision, made during vCenter deployment.

What Lives Inside Every vCenter 8.0 Appliance

Since vSphere 7.0, the external Platform Services Controller (PSC) is gone. Every vCenter Server appliance contains both the vCenter services and the authentication services:

ComponentRole
vCenter Single Sign-On (SSO)Authenticates users and issues tokens (Section 6.1)
VMware Directory Service (vmdir)Stores the SSO domain: users, groups, solution users, and global permissions, replicated between linked vCenters
VMware Certificate Authority (VMCA)Issues machine SSL, solution user, and ESXi certificates (Section 6.5)
Lookup ServiceRegisters each vCenter's service endpoints so linked instances can find each other
License ServiceStores license assignments for the domain
vCenter Server servicesvpxd, the vSphere Client, vLCM, content library, and other management services

An ESXi host is managed by one vCenter at a time. Adding it to a second vCenter disconnects it from the first.

Creating a New SSO Domain (4.1.1)

In Stage 2 of the first appliance's deployment, you choose Create a new SSO domain and enter:

  • the domain name (default vsphere.local), which should not match any Active Directory or OpenLDAP domain name you use,
  • the password for administrator@<domain>, the domain's built-in administrator.

The domain name is permanent for that domain, so choose it carefully.

Joining an Existing SSO Domain (4.1.2)

For each additional vCenter, choose Join an existing SSO domain in Stage 2 and provide the FQDN of a vCenter already in the domain plus the SSO administrator credentials. The new appliance replicates the domain's directory data and becomes part of an Enhanced Linked Mode (ELM) group.

Choice at Stage 2Result
Create a new SSO domainA standalone vCenter with its own domain, or the first node of a future ELM group
Join an existing SSO domainThe new vCenter is linked to every other vCenter in that domain

What Enhanced Linked Mode Gives You

vCenter Enhanced Linked Mode lets you log in to any single vCenter and view and manage the inventories of all vCenters in the group. You can join up to 15 vCenter Server appliances in one SSO domain. ELM shares:

  • One set of credentials across all linked vCenters, because they share the SSO domain,
  • Inventory view and search across every linked vCenter in a single vSphere Client session,
  • Roles, global permissions, tags, and categories, replicated through vmdir,
  • License visibility across the domain.

This answers a common design question. When five vCenters must be visible and searchable in one vSphere Client session with one set of credentials, deploy the first vCenter with a new SSO domain and join the other four to it.

ELM is not high availability. Each vCenter still manages only its own hosts, and losing one vCenter does not move its hosts to another. Use vCenter HA (Section 1.2) for availability.

Repointing and Removing vCenters

  • Repoint: cmsso-util domain-repoint moves a vCenter from one SSO domain to another existing domain, for example to merge two ELM groups or split one.
  • Unregister: When you decommission a vCenter, power it off and run cmsso-util unregister from another node in the domain. This removes the retired node's registration so other nodes stop replicating with it.

Operating an ELM Group Safely

  • Snapshots: Replication between linked vCenters means an online snapshot of just one node can corrupt the domain if you revert it. Broadcom's guidance is to shut down all linked appliances gracefully and snapshot them offline, at the same time, before changes such as certificate replacement, adding or retiring a vCenter, or updates. File-based backups remain the primary recovery method.
  • Time: Keep every appliance synchronized to the same time source. SSO tokens and directory replication both depend on accurate clocks.
  • Federation: When an ELM group uses Okta, Microsoft Entra ID, or PingFederate, you configure the provider on one vCenter and activate it on the others. All of them must run a release that supports that provider.

Scenario: Two Sites, One Management View

Situation: A company has a vCenter at each of two data centers. Operations wants one vSphere Client view of both, and occasionally needs to move running VMs between sites.

Options:

  • Enhanced Linked Mode (same SSO domain): Deploy (or repoint) both vCenters into one SSO domain. Administrators get one login and one inventory view, and VMs can move between the linked vCenters with the normal Migrate wizard. Cross vCenter vMotion inside one SSO domain has been available since vSphere 6.0.
  • Separate SSO domains: Keep each site independent, for example for isolation or different teams, and use Advanced Cross vCenter vMotion (Section 2.7) when a VM must move.

What ELM does not give you: automatic failover of one site's hosts to the other vCenter, or protection of vCenter itself. Those need vCenter HA (Section 1.2) and a DR solution such as SRM (Section 1.7).

Exam Traps

  • "Create" versus "join": Only the first vCenter creates the SSO domain. Every later vCenter joins it. Creating a second domain with the same name does not link the two.
  • Maximum 15: A 16th vCenter needs a second SSO domain.
  • Snapshots: Reverting one linked vCenter from an online snapshot can break replication for the whole domain. Use coordinated offline snapshots and file-based backups.
  • Hybrid Linked Mode is a different feature. It links an on-premises vCenter with a VMware cloud SDDC, not two on-premises vCenters.
Loading diagram...
Enhanced Linked Mode Topology
Test Your Knowledge

An administrator is deploying five new vCenter Server appliances. All inventories must be visible and searchable in one vSphere Client session, and administrators must use one set of credentials for all of them. What should the administrator do during Stage 2 of the deployments?

A

Create a new SSO domain on every appliance and configure Hybrid Linked Mode between them

B

Create a new SSO domain on the first appliance and have the other four join that existing SSO domain

C

Configure vCenter High Availability across all five appliances

D

Join all five appliances to the Active Directory domain using Integrated Windows Authentication

Test Your Knowledge

What is the maximum number of vCenter Server appliances that can be joined in a single vCenter Enhanced Linked Mode group?

A

5

B

10

C

15

D

25

Test Your Knowledge

After a company merger, an administrator must move a standalone vCenter Server from its own SSO domain into another company's existing SSO domain so that it joins their Enhanced Linked Mode group. Which approach does vSphere provide?

A

Repoint the vCenter to the other domain with cmsso-util domain-repoint

B

Rename the SSO domain from the VAMI so both domains have the same name

C

Export the inventory with Update Planner and import it into the target vCenter

D

Enable Advanced Cross vCenter vMotion between the two vCenter instances

Sections you finish are checked off in the contents.