VMware ESXi and vSphere Cluster Management
vCenter Single Sign-On Deployment Modes
Learn the historical vCenter SSO Basic, same-site, and multi-location deployment modes and choose a topology based on scale, availability, geography, and Linked Mode.
Purpose of vCenter Single Sign-On
vCenter Single Sign-On (SSO) is the authentication and identity-management component used by vCenter Server and related VMware management services. It validates administrator identities and helps connected services use a common authentication domain.
SSO topology is an installation-planning decision because it affects the number of SSO nodes, replication, availability, site placement, network requirements, and the way multiple vCenter Server systems are administered. Changing the design later may require a version-specific migration or redesign.
For background on the management platform, see VMware ESXi online course and VMware ESXi.
Overview of the Three Deployment Modes
An SSO node is an instance of the vCenter SSO service. In a multi-instance design, the nodes authenticate users and replicate SSO information between participating instances.
| Deployment mode | SSO node layout | Typical location design | Primary purpose | Replication | Linked Mode relevance | Suitable use case | Key planning considerations |
|---|---|---|---|---|---|---|---|
| Basic deployment | One SSO node | One site | Simple vCenter deployment | None between SSO nodes | Limited; does not provide a multisite SSO design | One vCenter Server with modest inventory | Simple installation, but no additional SSO node provides redundancy |
| Multiple instances in one location | One primary instance and one or more additional instances | One physical or logical site | SSO resiliency within the site | SSO information replicates among nodes | Useful when connected vCenter systems are at the same location, subject to release support | Single-site environments requiring SSO high availability | Requires replication planning, reliable connectivity, monitoring, and operational procedures |
| Multiple instances in multiple locations | Replicated SSO instances distributed across sites | Geographically separate locations | Distributed availability and administration | SSO information replicates between sites | Key historical use case for administering geographically dispersed vCenter Servers in Linked Mode | Multiple datacenters managed together | Requires reliable intersite networking, suitable latency, healthy replication, and separate failure domains |
Basic Deployment Mode
Basic deployment mode contains a single SSO node. It is the normal choice for a simple environment with one vCenter Server instance and no separate requirement for SSO service redundancy.
Historical planning guidance associated this mode with an inventory of up to 1,000 hosts and 10,000 virtual machines. These figures are planning guidance for the relevant architecture, not a promise that every release, workload, or configuration supports identical limits.
vCenter Server Appliance and Simple Install
In the relevant historical versions, the vCenter Server Appliance was associated with the Basic SSO option. The vCenter Simple Install workflow also streamlined installation using this basic, single-node SSO arrangement.
For a single-site organization with one vCenter Server managing 300 hosts and 2,500 virtual machines, Basic deployment is a reasonable selection when no additional SSO availability requirement exists. The inventory is below the stated planning guideline, and the environment has only one vCenter Server.
Primary limitation
A Basic deployment has no additional SSO node to continue providing the service if the single node becomes unavailable. It is therefore not an SSO high-availability design. Replicating data elsewhere as part of backup or disaster recovery does not change the live topology into a redundant SSO service.
Multiple SSO Instances in One Location
This topology contains a primary vCenter SSO instance and one or more additional SSO instances at the same physical or logical site. The instances replicate SSO information among themselves.
The main objective is High Availability (HA). HA is a design objective that reduces service interruption by using redundant components. If one SSO instance is unavailable, the remaining design may continue to support authentication, subject to the exact release, service dependencies, and supported configuration.
When to use it
Choose a same-location multi-instance design when the organization needs SSO resiliency inside one datacenter or site. For example, a central datacenter with several vCenter Server systems may require continued SSO service if one SSO instance fails, without requiring a cross-site administrative topology.
Operational requirements
- Define which instance is the primary and identify every additional SSO node.
- Plan reliable communication between all participating nodes.
- Monitor replication health and service availability.
- Use consistent name resolution, time synchronization, certificates, and network policies as required by the installed release.
- Document failure procedures and verify that the design is supported for the specific vSphere version.
Additional nodes increase resilience but also increase administrative responsibility. They are not automatically a complete backup or disaster-recovery solution.
Multiple SSO Instances in Multiple Locations
This topology distributes SSO instances across geographically separate sites. The instances replicate SSO information between locations, allowing the SSO environment to support a distributed vCenter Server design.
The key use case is a geographically dispersed vCenter Server deployment in which administrators need to administer connected vCenter Server systems through Linked Mode. Linked Mode is a vCenter capability for administering connected vCenter Server systems together.
Important planning factors
- Intersite reliability: Replication partners must communicate consistently across the site network.
- Latency: Confirm that the latency and bandwidth characteristics meet the requirements of the exact release.
- Replication health: Monitor synchronization and investigate divergence promptly.
- Failure-domain separation: Place nodes so that a single site, power domain, or network failure does not remove every participating instance.
- Time and name services: Verify time synchronization and name resolution across sites.
- Linked Mode support: Confirm that the desired vCenter relationship and cross-site topology are supported by the installed version.
Distributed replication improves availability and supports a multisite administration model, but it is not the same as a disaster-recovery plan. Backups, recovery testing, data protection, and documented site-failure procedures are still required.
Deployment Mode Selection Matrix
| Requirement | Basic deployment | Multiple instances in one location | Multiple instances in multiple locations |
|---|---|---|---|
| One vCenter Server | Recommended starting point | Possible when same-site SSO HA is required | Usually unnecessary unless the design also spans sites |
| Up to 1,000 hosts and 10,000 virtual machines | Historical planning fit | Use when availability requirements justify extra nodes | Use only when geographic and administrative requirements also apply |
| vCenter Server Appliance use | Historically associated with this mode | Verify support in the exact release | Verify support in the exact release |
| SSO high availability | No additional SSO node; not redundant | Designed for same-site SSO resiliency | Designed for distributed SSO resiliency |
| Geographically separate sites | Not the intended topology | Not the intended topology | Primary historical use case |
| Linked Mode administration | Does not provide the multisite design by itself | May apply to same-site connected systems, subject to release support | Key historical use case for geographically dispersed vCenter Servers |
| Replication requirement | None between SSO nodes | Replication among same-site instances | Replication between instances at separate sites |
How to Select a Topology
- Identify the exact vSphere and vCenter Server version. Terms such as SSO, Simple Install, Linked Mode, and vCenter Server Appliance are version-dependent.
- Count the vCenter Server systems and determine whether they are in one site or multiple sites.
- Record the expected inventory size, including hosts and virtual machines.
- Decide whether SSO service redundancy is required. Separate same-site availability from geographic availability.
- Determine whether administrators need Linked Mode for connected vCenter Server systems.
- For a single, modest-scale vCenter environment, select Basic deployment when no SSO HA requirement exists.
- For SSO HA within one site, evaluate multiple SSO instances in the same location.
- For geographically dispersed vCenter Servers that require a supported Linked Mode arrangement, evaluate multiple SSO instances across multiple locations.
- Document the topology before starting the relevant installation workflow, including the primary instance, additional nodes, site placement, and replication connectivity.
Topology Planning Configuration
This topic is primarily architectural; it does not require a command-line procedure. Create a planning record before installation.
SSO deployment mode: Basic | Multiple instances, one location | Multiple instances, multiple locations
Primary SSO instance: [name]
Additional SSO nodes: [names]
Site placement: [site and failure domain for each node]
Replication paths: [source, destination, and network dependency]
Linked Mode requirement: Yes | No
vCenter Server instances: [list]
Inventory estimate: [hosts] hosts, [virtual machines] virtual machines
Version-specific validation: [release documentation reviewed]Do not infer ports, installation screens, migration procedures, or supported node combinations from a different release. Use procedures and tools documented for the exact vSphere version.
Replication, Availability, and Disaster Recovery
Replication is the synchronization of SSO information between multiple SSO instances. It helps participating nodes maintain compatible identity data, but it is not a complete backup.
- Same-site availability protects against the loss of one SSO node while the site and its shared dependencies remain available.
- Geographically distributed availability separates nodes across locations and can reduce the impact of a site failure, provided intersite dependencies and the supported design are properly handled.
- Backup and disaster recovery require separate protection, recovery procedures, and testing. Replication alone does not replace them.
- Communication health is essential. All participating nodes must be able to communicate reliably enough for authentication and replication operations.
Troubleshooting Topology Problems
Basic deployment was selected, but SSO high availability is now required
The initial topology did not account for an SSO redundancy requirement. First determine whether the requirement is same-site availability or multisite availability. Then review the supported migration or redesign paths for the installed vSphere version. Do not assume that adding an arbitrary node creates a supported HA configuration.
SSO information is inconsistent between instances
Impaired replication connectivity or replication health is a likely cause. Verify reachability between every participating node, then review replication status and service health using release-specific tools. Check name resolution, time synchronization, certificates, and network reliability as applicable. Restore communication and repair replication according to the procedures for that version.
Linked Mode is needed across sites, but the design is single-node or single-site
Confirm the locations of the vCenter Server systems and the desired cross-site administrative model. Validate the supported topology for the release. If appropriate, redesign using the supported multi-location SSO model rather than treating a single-node or same-site design as equivalent.
The installer does not contain the expected SSO choices
The planning material may describe a different product generation. Identify the exact vCenter Server and vSphere version, compare its identity and availability architecture with the historical node-based SSO model, and use documentation matching the installed release.
Exam-Relevant Notes
- Basic deployment means one SSO node.
- The historical Basic planning guideline is up to 1,000 hosts and 10,000 virtual machines.
- Multiple instances in one location target SSO resiliency within a site.
- Multiple instances in multiple locations target distributed deployments and historically relate to Linked Mode administration across sites.
- Multi-instance designs replicate SSO information, but replication is not the same as backup or disaster recovery.
- Choose the mode only after evaluating inventory scale, vCenter count, availability objectives, site distribution, and version support.
Related Planning Topics
Continue with communication between vCenter Server and ESXi, assigning permissions, and the vSphere access control system to connect SSO authentication with authorization and host management.