Broadcom Publishes the VCF 9.1 Identity Design Best Practices Whitepaper

Identity Broker topology, SSO models, IdP federation, and role governance the official design guidance for the layer with the longest architectural shadow. Read it before you write the HLD.

Share

Broadcom has published a whitepaper on VCF 9.1 Identity Design Best Practices official design guidance for the identity architecture introduced with VCF 9.x and matured in 9.1. If you’ve been following this series, you’ll know I consider identity the Day 0 decision with the longest shadow: it touches who can deploy a workload domain, who can self-service a Kubernetes cluster, who sees which tenant’s cost data, and who can patch which cluster. This whitepaper is the official companion to those decisions.

What it covers

• VCF Identity Broker the consolidated identity layer within VCF Management Services, and the deployment model decision (single node vs three-node cluster) that determines control plane authentication resilience.

• VCF Single Sign-On models design requirements, recommendations, and trade-offs per SSO topology, across single-instance and multi-instance fleet designs.

• Identity provider federation Azure AD/Entra, Okta, Ping, ADFS, and generic OIDC, and how the enterprise IdP strategy maps onto the platform.

• VCF Roles and centralised access management custom roles mapped to component permissions, VCF-level role assignment, OAuth 2.0 API tokens for service accounts, and vCenter role sync and remediation across instances and fleets.

How I’d use it

Three reading audiences, three uses. If you’re designing a new VCF 9.1 environment: read it before the HLD identity section is drafted the broker topology and federation scope decisions belong in the first design workshop, not the last. If you’re operating an existing 9.x estate: use it as the benchmark for an identity architecture review; the gap between current state and the documented best practices is your remediation backlog, prioritised. If you’re carrying a VIDM estate through a 5.x to 9.x upgrade: pair it with the scripted VIDM-to-Identity-Broker migration workflow the whitepaper defines the target state the migration should land on, which is exactly the moment to rationalise years of accumulated group-to-role debt rather than lifting it verbatim.

For the field-guide treatment of these decisions including the Day 0/1/2 operational framing and the MGL-pattern trade-off between VCF SSO governance simplicity and per-product SSO operational autonomy see Part 33 (Identity Broker and SSO Federation) and Part 40 (VIDM to Identity Broker Migration) of this series.

Download

Broadcom VCF 9.1 Identity Design Best Practices (Whitepaper PDF)
Broadcom TechDocs VCF Identity Broker Detailed Design

Broadcom Strengthen Zero Trust Platform Security and Resilience with VCF 9.1

Broadcom Announcing VCF 9.1: Modern Private Cloud Built for Efficiency and Resilience