License Management — VCF 9.0 Licensing Model
Objectives
- Explain the evolution from license keys to license files in VCF 9.0
- Describe per-vCenter licensing (not per-host) and CPU core-based auto-claiming
- Navigate VCF Business Services (VCFBS) console for connected/disconnected mode
- List products still using legacy license keys (Live Recovery, vDefend, Avi, Private AI, Tanzu)
- Perform license registration, assignment, and usage reporting in VCF Operations
- Explain subscription expiry behavior (60-day warning → 90-day grace → host disconnect)
Prerequisites
Active Holodeck VCF 9.0 lab or access to VCF documentation
Required skills:
- Basic VMware terminology
Tasks
Task 1 VCF 9.0 Licensing Model
Understand the new license file model replacing legacy license keys
VCF 5.x: license keys per component, no consumption data required, major-version-specific, managed in Broadcom Support Portal. VCF 9.0: single digitally signed license FILE for all components, consumption data required, version-agnostic, managed in VCF Business Services (VCFBS) console. License file benefits: auto-pooling, splitting/merging doesn't invalidate, secure (forgery prevention).
[HOLODECK NOTE] Holodeck deployments use evaluation licenses (90-day). The VCFBS console registration and license file workflow cannot be fully tested in Holodeck without a valid Broadcom subscription. Connected mode (automatic license sync) requires internet access from the VCF Operations appliance — Holodeck environments are typically air-gapped or NAT'd. Focus study on understanding the workflow conceptually rather than hands-on license management in Holodeck.
VCF 9.0 = per-vCenter licensing (not per-host). ESX hosts auto-claim licenses from attached vCenter based on CPU core count. A vCenter can be assigned one license file. One allocation can serve many vCenter instances (if entitlements suffice). New ESX hosts get 90-day evaluation period. vCenter and ESX must be 9.0+ to use license files.
VCFBS = new license management portal. Tenants and users managed with Broadcom credentials. License entitlements distributed across tenants. Connected mode: VCF Operations auto-registers with VCFBS. Disconnected mode: manual download/upload of registration files and license files. Usage info flows to VCFBS for compliance — prevents overallocation.
Still using legacy license keys: Live Recovery, vDefend, Avi Load Balancer, VMware Private AI, Tanzu. These products managed separately — not through VCF 9.0 license file system.
Validation Gate
Check: Calculate the core license count for: 8 hosts, each with 2× 32-core CPUs
Expected: 8 hosts × 2 sockets × 32 cores = 512 cores to license. This is the base count — add-ons are also per-core on top of base VCF subscription.
Common Errors
Task 2 License Management in VCF Operations
Manage licenses through VCF Operations console
Workflow: License Management > Registration in VCF Operations. Connected: auto-registration, activation code created. Disconnected: download registration file from VCF Ops → upload to VCFBS → download signed license file → import to VCF Ops. After registration: assign licenses + add-ons (e.g., vSAN) to vCenter instances. ESX hosts auto-licensed when added to vCenter.
Connected mode: usage reports generated automatically. Disconnected mode: generate signed gzip usage report → upload to VCFBS to refresh license info. License consumption and capacity visible in VCF Operations console. Entitlement validation: signature, feature set/components/expiration, capacity.
Expiry notification: 60 days before subscription end (alerts in VCF Ops + vCenter + emails from VCFBS). Grace period: 90 days after expiry. After 90 days without renewal: ESX hosts disconnected from vCenter, running VMs continue but no new VMs can be powered on, no changes allowed. During upgrade from VCF 5.x: licenses reset to 90-day evaluation mode to enable transition to new model. Precise expiry behavior: (1) 60 days before expiry — alerts appear in both VCF Operations and vCenter; emails sent from VCFBS console. (2) On expiry — 90-day grace period begins; customer remains notified; renewal during grace period causes no disruption. (3) After 90-day grace — VCF expiration invoked: ALL affected ESX hosts are disconnected from their respective vCenter instances; running VMs continue to run but no additional VMs can be powered on; no changes allowed to the VCF instance. (4) On renewal after expiration — hosts automatically reconnect and normal operations resume.
Validation Gate
Check: Where in VCF do you manage and monitor license compliance?
Expected: SDDC Manager Administration → Licensing. Shows license keys, assigned components, compliance status. VCF Operations also provides license usage dashboards across the fleet.
Common Errors
Design Reflection (VCDX)
Licensing is always a VCDX defense topic — panelists ask about cost per VM, TCO comparisons with public cloud, and whether your licensing covers the add-ons your design requires. Know your per-core count and be able to calculate licensing cost on the spot.
Requirements
- Understand VCF 9.0 per-core subscription licensing model
- Calculate core counts for licensing
- Track license compliance across domains
Constraints
- Per-core licensing — no per-VM or per-socket option in 9.0
- Add-ons require separate per-core subscriptions
- Evaluation licenses expire after 60 days
Assumptions
- Customer has purchased appropriate VCF edition for their requirements
- License keys are applied during or immediately after bring-up
Risks
- Under-licensing causing compliance issues and support eligibility impact
- Budget overrun from add-on licensing not included in initial estimates
⚠ Known Pitfalls (from Community KB)
References
- VCF 9.0 Licensing GuideTier 1 — Official