6.5 License Management in VMware Cloud Foundation
Key Takeaways
- From version 9.0 you license VCF and vSphere Foundation using a VCF Operations instance together with the VMware Cloud Foundation Business Services console at vcf.broadcom.com.
- Traditional 25-character license keys are eliminated for version 9 products; entitlement is a term-based subscription with a capacity allocation instead.
- At least one license server must be added to each VCF Operations instance used for license management; it is a protected repository that holds the licensing data.
- Licenses are assigned to vCenter instances, and the components connected to that vCenter — ESX hosts, NSX, HCX, and automation tooling — are licensed automatically as a result.
- Primary licenses cover VCF and vSphere Foundation and are measured in CPU cores, while add-on licenses cover vSAN capacity in TiB and VMware Private AI Foundation with NVIDIA in cores.
6.5 License Management in VMware Cloud Foundation
Exam Focus: "Given a scenario, configure license management within VMware Cloud Foundation" is an explicit blueprint objective, and it is one of the areas most transformed by the move to VCF 9.0. Candidates who learned VCF on 5.x will recall pasting 25-character keys into SDDC Manager. That model no longer exists for version 9 products.
What Changed, and Why It Matters
The shift from the 8.x model is fundamental rather than cosmetic:
| Earlier VCF / vSphere | VCF 9.0 and later | |
|---|---|---|
| Entitlement artifact | 25-character license keys per component | Term-based subscription with a capacity allocation; keys are eliminated |
| Where managed | SDDC Manager and vCenter, per component | VCF Operations plus the VCF Business Services console (vcf.broadcom.com) |
| Assignment target | Each component licensed individually | The vCenter instance; connected components inherit |
| Local store | Held in the component's own inventory | A dedicated license server appliance |
The Two Halves of the System
The Business Services Console
vcf.broadcom.com is the central licensing hub. It is where an organisation manages subscriptions, views available capacity, and handles license distribution. It is Broadcom-hosted and sits outside the customer environment.
The VCF Operations Instance
Inside the environment, a VCF Operations instance acts as the local licensing manager. It must be registered with the Business Services console, and registration happens in one of two modes:
- Connected mode (recommended) — VCF Operations synchronises licensing data with the console automatically.
- Disconnected mode — for environments with no path to Broadcom, licensing is maintained through manual license file uploads.
The License Server
Between those two halves sits the license server: a protected repository within the environment that holds the licensing data.
The operational rules worth memorising:
- At least one license server must be added to each VCF Operations instance used for license management. A VCF Operations instance without one cannot license anything.
- Once the license server is added, licenses must then be added to it before any vCenter or other asset can be licensed. Adding the server is a prerequisite, not the completion of the task.
- A license server is deployed during new VCF and vSphere Foundation deployments, and during upgrades to version 9.1 and later. From 9.1 the license server is one of the default VCF management services the installer deploys.
Primary and Add-On Licenses
Two categories exist, and the unit of measure differs:
| Category | Covers | Measured in |
|---|---|---|
| Primary | VMware Cloud Foundation, VMware vSphere Foundation | CPU cores |
| Add-on | vSAN capacity | TiB |
| Add-on | VMware Private AI Foundation with NVIDIA | Cores |
An add-on supplements a primary license rather than standing alone, so vSAN capacity entitlement sits on top of a core-based VCF or vSphere Foundation entitlement.
The Default License
The system automatically creates a default license — a capacity pool assembled from all active subscriptions of the same product within your Site ID. This is what allows capacity to be consumed without hand-allocating an entitlement to every instance, and it is why the Site ID matters: subscriptions pool within a site boundary.
Version 8.x Coexistence
A subscription delivers both a version 9+ default license and license keys for version 8.x of the product. Estates mid-migration therefore hold both artifacts simultaneously, which is deliberate rather than a defect.
The Assignment Model
This is the single most examinable behavioural change:
You assign licenses to vCenter instances. The components connected to that vCenter — ESX hosts, NSX, HCX, and automation tooling — are then licensed automatically.
The practical consequences:
- Adding hosts to a licensed vCenter does not require a separate licensing step, though it does consume core capacity from the pool.
- Licensing scope collapses from managing many individual component licenses to managing product capacity allocations.
- Capacity, not key placement, becomes the thing to monitor. Running out means insufficient subscribed cores rather than an unlicensed component.
Configuring License Management: The Order of Operations
- Deploy or identify the VCF Operations instance that will act as licensing manager.
- Register it with the Business Services console in connected or disconnected mode.
- Add at least one license server to that VCF Operations instance.
- Add licenses to the license server.
- Assign licenses to vCenter instances, which licenses their connected components.
- Monitor consumed against subscribed capacity.
Exam Watch: Key Scenarios and Candidate Traps
[!WARNING] Do not select "enter the license key in SDDC Manager". Version 9 products have no 25-character keys, and the SDDC Manager UI is deprecated. Licensing runs through VCF Operations and the Business Services console.
[!IMPORTANT] Adding the license server is step three, not the last step. A scenario in which an administrator has added a license server but still cannot license a vCenter is almost always missing the step of adding licenses to that server.
[!TIP] Disconnected sites are supported. If a scenario stipulates no internet connectivity, the answer is disconnected-mode registration with manual license file uploads, not an unlicensed or evaluation-mode deployment.
An administrator upgrading from VCF 5.x asks where to enter the 25-character license keys for the newly deployed VCF 9.0 components. What is the correct response?
An administrator has registered a VCF Operations instance with the Business Services console and added a license server, but still cannot license a vCenter instance. What step has most likely been missed?
In the VCF 9.0 licensing model, what is the direct effect of assigning a license to a vCenter instance?
A secure facility has no network path to Broadcom services but must run a fully licensed VCF 9.0 environment. Which approach is supported?