VMware ESXi and vSphere Cluster Management

vCenter Single Sign-On Deployment Modes

Learn the historical vCenter SSO Basic, same-site, and multi-location deployment modes and choose a topology based on scale, availability, geography, and Linked Mode.

Purpose of vCenter Single Sign-On

vCenter Single Sign-On (SSO) is the authentication and identity-management component used by vCenter Server and related VMware management services. It validates administrator identities and helps connected services use a common authentication domain.

SSO topology is an installation-planning decision because it affects the number of SSO nodes, replication, availability, site placement, network requirements, and the way multiple vCenter Server systems are administered. Changing the design later may require a version-specific migration or redesign.

For background on the management platform, see VMware ESXi online course and VMware ESXi.

Overview of the Three Deployment Modes

An SSO node is an instance of the vCenter SSO service. In a multi-instance design, the nodes authenticate users and replicate SSO information between participating instances.

Deployment modeSSO node layoutTypical location designPrimary purposeReplicationLinked Mode relevanceSuitable use caseKey planning considerations
Basic deploymentOne SSO nodeOne siteSimple vCenter deploymentNone between SSO nodesLimited; does not provide a multisite SSO designOne vCenter Server with modest inventorySimple installation, but no additional SSO node provides redundancy
Multiple instances in one locationOne primary instance and one or more additional instancesOne physical or logical siteSSO resiliency within the siteSSO information replicates among nodesUseful when connected vCenter systems are at the same location, subject to release supportSingle-site environments requiring SSO high availabilityRequires replication planning, reliable connectivity, monitoring, and operational procedures
Multiple instances in multiple locationsReplicated SSO instances distributed across sitesGeographically separate locationsDistributed availability and administrationSSO information replicates between sitesKey historical use case for administering geographically dispersed vCenter Servers in Linked ModeMultiple datacenters managed togetherRequires reliable intersite networking, suitable latency, healthy replication, and separate failure domains

Basic Deployment Mode

Basic deployment mode contains a single SSO node. It is the normal choice for a simple environment with one vCenter Server instance and no separate requirement for SSO service redundancy.

Historical planning guidance associated this mode with an inventory of up to 1,000 hosts and 10,000 virtual machines. These figures are planning guidance for the relevant architecture, not a promise that every release, workload, or configuration supports identical limits.

vCenter Server Appliance and Simple Install

In the relevant historical versions, the vCenter Server Appliance was associated with the Basic SSO option. The vCenter Simple Install workflow also streamlined installation using this basic, single-node SSO arrangement.

For a single-site organization with one vCenter Server managing 300 hosts and 2,500 virtual machines, Basic deployment is a reasonable selection when no additional SSO availability requirement exists. The inventory is below the stated planning guideline, and the environment has only one vCenter Server.

Primary limitation

A Basic deployment has no additional SSO node to continue providing the service if the single node becomes unavailable. It is therefore not an SSO high-availability design. Replicating data elsewhere as part of backup or disaster recovery does not change the live topology into a redundant SSO service.

Multiple SSO Instances in One Location

This topology contains a primary vCenter SSO instance and one or more additional SSO instances at the same physical or logical site. The instances replicate SSO information among themselves.

The main objective is High Availability (HA). HA is a design objective that reduces service interruption by using redundant components. If one SSO instance is unavailable, the remaining design may continue to support authentication, subject to the exact release, service dependencies, and supported configuration.

When to use it

Choose a same-location multi-instance design when the organization needs SSO resiliency inside one datacenter or site. For example, a central datacenter with several vCenter Server systems may require continued SSO service if one SSO instance fails, without requiring a cross-site administrative topology.

Operational requirements

  • Define which instance is the primary and identify every additional SSO node.
  • Plan reliable communication between all participating nodes.
  • Monitor replication health and service availability.
  • Use consistent name resolution, time synchronization, certificates, and network policies as required by the installed release.
  • Document failure procedures and verify that the design is supported for the specific vSphere version.

Additional nodes increase resilience but also increase administrative responsibility. They are not automatically a complete backup or disaster-recovery solution.

Multiple SSO Instances in Multiple Locations

This topology distributes SSO instances across geographically separate sites. The instances replicate SSO information between locations, allowing the SSO environment to support a distributed vCenter Server design.

The key use case is a geographically dispersed vCenter Server deployment in which administrators need to administer connected vCenter Server systems through Linked Mode. Linked Mode is a vCenter capability for administering connected vCenter Server systems together.

Important planning factors

  • Intersite reliability: Replication partners must communicate consistently across the site network.
  • Latency: Confirm that the latency and bandwidth characteristics meet the requirements of the exact release.
  • Replication health: Monitor synchronization and investigate divergence promptly.
  • Failure-domain separation: Place nodes so that a single site, power domain, or network failure does not remove every participating instance.
  • Time and name services: Verify time synchronization and name resolution across sites.
  • Linked Mode support: Confirm that the desired vCenter relationship and cross-site topology are supported by the installed version.

Distributed replication improves availability and supports a multisite administration model, but it is not the same as a disaster-recovery plan. Backups, recovery testing, data protection, and documented site-failure procedures are still required.

Deployment Mode Selection Matrix

RequirementBasic deploymentMultiple instances in one locationMultiple instances in multiple locations
One vCenter ServerRecommended starting pointPossible when same-site SSO HA is requiredUsually unnecessary unless the design also spans sites
Up to 1,000 hosts and 10,000 virtual machinesHistorical planning fitUse when availability requirements justify extra nodesUse only when geographic and administrative requirements also apply
vCenter Server Appliance useHistorically associated with this modeVerify support in the exact releaseVerify support in the exact release
SSO high availabilityNo additional SSO node; not redundantDesigned for same-site SSO resiliencyDesigned for distributed SSO resiliency
Geographically separate sitesNot the intended topologyNot the intended topologyPrimary historical use case
Linked Mode administrationDoes not provide the multisite design by itselfMay apply to same-site connected systems, subject to release supportKey historical use case for geographically dispersed vCenter Servers
Replication requirementNone between SSO nodesReplication among same-site instancesReplication between instances at separate sites

How to Select a Topology

  1. Identify the exact vSphere and vCenter Server version. Terms such as SSO, Simple Install, Linked Mode, and vCenter Server Appliance are version-dependent.
  2. Count the vCenter Server systems and determine whether they are in one site or multiple sites.
  3. Record the expected inventory size, including hosts and virtual machines.
  4. Decide whether SSO service redundancy is required. Separate same-site availability from geographic availability.
  5. Determine whether administrators need Linked Mode for connected vCenter Server systems.
  6. For a single, modest-scale vCenter environment, select Basic deployment when no SSO HA requirement exists.
  7. For SSO HA within one site, evaluate multiple SSO instances in the same location.
  8. For geographically dispersed vCenter Servers that require a supported Linked Mode arrangement, evaluate multiple SSO instances across multiple locations.
  9. Document the topology before starting the relevant installation workflow, including the primary instance, additional nodes, site placement, and replication connectivity.

Topology Planning Configuration

This topic is primarily architectural; it does not require a command-line procedure. Create a planning record before installation.

SSO deployment mode: Basic | Multiple instances, one location | Multiple instances, multiple locations
Primary SSO instance: [name]
Additional SSO nodes: [names]
Site placement: [site and failure domain for each node]
Replication paths: [source, destination, and network dependency]
Linked Mode requirement: Yes | No
vCenter Server instances: [list]
Inventory estimate: [hosts] hosts, [virtual machines] virtual machines
Version-specific validation: [release documentation reviewed]

Do not infer ports, installation screens, migration procedures, or supported node combinations from a different release. Use procedures and tools documented for the exact vSphere version.

Replication, Availability, and Disaster Recovery

Replication is the synchronization of SSO information between multiple SSO instances. It helps participating nodes maintain compatible identity data, but it is not a complete backup.

  • Same-site availability protects against the loss of one SSO node while the site and its shared dependencies remain available.
  • Geographically distributed availability separates nodes across locations and can reduce the impact of a site failure, provided intersite dependencies and the supported design are properly handled.
  • Backup and disaster recovery require separate protection, recovery procedures, and testing. Replication alone does not replace them.
  • Communication health is essential. All participating nodes must be able to communicate reliably enough for authentication and replication operations.

Troubleshooting Topology Problems

Basic deployment was selected, but SSO high availability is now required

The initial topology did not account for an SSO redundancy requirement. First determine whether the requirement is same-site availability or multisite availability. Then review the supported migration or redesign paths for the installed vSphere version. Do not assume that adding an arbitrary node creates a supported HA configuration.

SSO information is inconsistent between instances

Impaired replication connectivity or replication health is a likely cause. Verify reachability between every participating node, then review replication status and service health using release-specific tools. Check name resolution, time synchronization, certificates, and network reliability as applicable. Restore communication and repair replication according to the procedures for that version.

Linked Mode is needed across sites, but the design is single-node or single-site

Confirm the locations of the vCenter Server systems and the desired cross-site administrative model. Validate the supported topology for the release. If appropriate, redesign using the supported multi-location SSO model rather than treating a single-node or same-site design as equivalent.

The installer does not contain the expected SSO choices

The planning material may describe a different product generation. Identify the exact vCenter Server and vSphere version, compare its identity and availability architecture with the historical node-based SSO model, and use documentation matching the installed release.

Exam-Relevant Notes

  • Basic deployment means one SSO node.
  • The historical Basic planning guideline is up to 1,000 hosts and 10,000 virtual machines.
  • Multiple instances in one location target SSO resiliency within a site.
  • Multiple instances in multiple locations target distributed deployments and historically relate to Linked Mode administration across sites.
  • Multi-instance designs replicate SSO information, but replication is not the same as backup or disaster recovery.
  • Choose the mode only after evaluating inventory scale, vCenter count, availability objectives, site distribution, and version support.

Related Planning Topics

Continue with communication between vCenter Server and ESXi, assigning permissions, and the vSphere access control system to connect SSO authentication with authorization and host management.