1.5 vCenter Topology: SSO Domains & Enhanced Linked Mode
Key Takeaways
Every vCenter Server 8.0 appliance embeds its own authentication services (SSO, VMCA, Lookup Service, and VMware Directory Service); the external Platform Services Controller no longer exists.
During Stage 2 of deployment, the first vCenter creates a new vCenter Single Sign-On domain and later vCenters join that existing domain to form Enhanced Linked Mode.
vCenter Enhanced Linked Mode joins up to 15 vCenter Server appliances in a single vSphere SSO domain, so one login shows and searches every linked inventory.
A vCenter can be moved to another SSO domain with cmsso-util domain-repoint, and a node is removed from a domain with cmsso-util unregister.
Broadcom recommends powered-off snapshots of all linked vCenter appliances, taken together, before risky changes in an Enhanced Linked Mode group.
1.5 vCenter Topology: SSO Domains & Enhanced Linked Mode
Objective 1.2 asks you to describe the components and topology of a vCenter architecture, and objectives 4.1.1 and 4.1.2 ask you to configure a new Single Sign-On domain and join an existing one. They are all the same design decision, made during vCenter deployment.
What Lives Inside Every vCenter 8.0 Appliance
Since vSphere 7.0, the external Platform Services Controller (PSC) is gone. Every vCenter Server appliance contains both the vCenter services and the authentication services:
| Component | Role |
|---|---|
| vCenter Single Sign-On (SSO) | Authenticates users and issues tokens (Section 6.1) |
| VMware Directory Service (vmdir) | Stores the SSO domain: users, groups, solution users, and global permissions, replicated between linked vCenters |
| VMware Certificate Authority (VMCA) | Issues machine SSL, solution user, and ESXi certificates (Section 6.5) |
| Lookup Service | Registers each vCenter's service endpoints so linked instances can find each other |
| License Service | Stores license assignments for the domain |
| vCenter Server services | vpxd, the vSphere Client, vLCM, content library, and other management services |
An ESXi host is managed by one vCenter at a time. Adding it to a second vCenter disconnects it from the first.
Creating a New SSO Domain (4.1.1)
In Stage 2 of the first appliance's deployment, you choose Create a new SSO domain and enter:
- the domain name (default
vsphere.local), which should not match any Active Directory or OpenLDAP domain name you use, - the password for
administrator@<domain>, the domain's built-in administrator.
The domain name is permanent for that domain, so choose it carefully.
Joining an Existing SSO Domain (4.1.2)
For each additional vCenter, choose Join an existing SSO domain in Stage 2 and provide the FQDN of a vCenter already in the domain plus the SSO administrator credentials. The new appliance replicates the domain's directory data and becomes part of an Enhanced Linked Mode (ELM) group.
| Choice at Stage 2 | Result |
|---|---|
| Create a new SSO domain | A standalone vCenter with its own domain, or the first node of a future ELM group |
| Join an existing SSO domain | The new vCenter is linked to every other vCenter in that domain |
What Enhanced Linked Mode Gives You
vCenter Enhanced Linked Mode lets you log in to any single vCenter and view and manage the inventories of all vCenters in the group. You can join up to 15 vCenter Server appliances in one SSO domain. ELM shares:
- One set of credentials across all linked vCenters, because they share the SSO domain,
- Inventory view and search across every linked vCenter in a single vSphere Client session,
- Roles, global permissions, tags, and categories, replicated through vmdir,
- License visibility across the domain.
This answers a common design question. When five vCenters must be visible and searchable in one vSphere Client session with one set of credentials, deploy the first vCenter with a new SSO domain and join the other four to it.
ELM is not high availability. Each vCenter still manages only its own hosts, and losing one vCenter does not move its hosts to another. Use vCenter HA (Section 1.2) for availability.
Repointing and Removing vCenters
- Repoint:
cmsso-util domain-repointmoves a vCenter from one SSO domain to another existing domain, for example to merge two ELM groups or split one. - Unregister: When you decommission a vCenter, power it off and run
cmsso-util unregisterfrom another node in the domain. This removes the retired node's registration so other nodes stop replicating with it.
Operating an ELM Group Safely
- Snapshots: Replication between linked vCenters means an online snapshot of just one node can corrupt the domain if you revert it. Broadcom's guidance is to shut down all linked appliances gracefully and snapshot them offline, at the same time, before changes such as certificate replacement, adding or retiring a vCenter, or updates. File-based backups remain the primary recovery method.
- Time: Keep every appliance synchronized to the same time source. SSO tokens and directory replication both depend on accurate clocks.
- Federation: When an ELM group uses Okta, Microsoft Entra ID, or PingFederate, you configure the provider on one vCenter and activate it on the others. All of them must run a release that supports that provider.
Scenario: Two Sites, One Management View
Situation: A company has a vCenter at each of two data centers. Operations wants one vSphere Client view of both, and occasionally needs to move running VMs between sites.
Options:
- Enhanced Linked Mode (same SSO domain): Deploy (or repoint) both vCenters into one SSO domain. Administrators get one login and one inventory view, and VMs can move between the linked vCenters with the normal Migrate wizard. Cross vCenter vMotion inside one SSO domain has been available since vSphere 6.0.
- Separate SSO domains: Keep each site independent, for example for isolation or different teams, and use Advanced Cross vCenter vMotion (Section 2.7) when a VM must move.
What ELM does not give you: automatic failover of one site's hosts to the other vCenter, or protection of vCenter itself. Those need vCenter HA (Section 1.2) and a DR solution such as SRM (Section 1.7).
Exam Traps
- "Create" versus "join": Only the first vCenter creates the SSO domain. Every later vCenter joins it. Creating a second domain with the same name does not link the two.
- Maximum 15: A 16th vCenter needs a second SSO domain.
- Snapshots: Reverting one linked vCenter from an online snapshot can break replication for the whole domain. Use coordinated offline snapshots and file-based backups.
- Hybrid Linked Mode is a different feature. It links an on-premises vCenter with a VMware cloud SDDC, not two on-premises vCenters.
An administrator is deploying five new vCenter Server appliances. All inventories must be visible and searchable in one vSphere Client session, and administrators must use one set of credentials for all of them. What should the administrator do during Stage 2 of the deployments?
Create a new SSO domain on every appliance and configure Hybrid Linked Mode between them
Create a new SSO domain on the first appliance and have the other four join that existing SSO domain
Configure vCenter High Availability across all five appliances
Join all five appliances to the Active Directory domain using Integrated Windows Authentication
What is the maximum number of vCenter Server appliances that can be joined in a single vCenter Enhanced Linked Mode group?
5
10
15
25
After a company merger, an administrator must move a standalone vCenter Server from its own SSO domain into another company's existing SSO domain so that it joins their Enhanced Linked Mode group. Which approach does vSphere provide?
Repoint the vCenter to the other domain with cmsso-util domain-repoint
Rename the SSO domain from the VAMI so both domains have the same name
Export the inventory with Update Planner and import it into the target vCenter
Enable Advanced Cross vCenter vMotion between the two vCenter instances
Sections you finish are checked off in the contents.