> ## Content Index
> Fetch the complete content index at: https://www.mohammadsiddiqui.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# What You Already Paid For and Haven't Switched On
- URL: https://www.mohammadsiddiqui.com/what-you-already-paid-for-and-havent-switched-on/
- Published: 2026-10-04T00:12:50.000Z
- Updated: 2026-10-04T00:12:50.000Z
- Description: A customer asked what database monitoring would cost. Ten minutes in it was clear they already had it. Entitled, not deployed, nobody had looked.
- Author: Mohammad Siddiqui
- Tags: operations, architecture

A customer asked me a few months back what it would cost to add database monitoring. We went through it, and about ten minutes in it became clear they already had it. Entitled, not deployed, nobody had looked.

That is not unusual. It happens because entitlements change at renewal, deployments change on project boundaries, and the two almost never get reconciled. So capability arrives quietly and sits there.

Here is the list I'd work through. None of it needs new spend. Some of it needs an afternoon.

One caveat up front

Editions differ, and several things below are VCF or VCF Edge only rather than vSphere Foundation. I've flagged which. Check your own entitlement against the [feature comparison](https://www.vmware.com/docs/vmware-cloud-foundation-9-1-feature-comparison-and-upgrade-paths?ref=mohammadsiddiqui.com) before you get excited about any particular line.

## Monitoring you probably already own

Management packs, eleven of them 

Five are databases: SQL Server, Oracle, PostgreSQL, MySQL and MongoDB. Two cover infrastructure reach, Network Devices and SNMP. Three are platform and integration, ServiceNow, Orchestrator and Aggregator. One is Kubernetes. They all reached GA at 9.1.1, rebuilt to carry log content as well as metrics because log management converged into VCF Operations. Infrastructure packs are available across editions. The application and database ones are VCF or VCF Edge only, which is the boundary that catches people. Packs are on the [marketplace](https://vcf.broadcom.com/vsc/?ref=mohammadsiddiqui.com) and the convergence detail is in the [Operations for Integrations release notes](https://techdocs.broadcom.com/us/en/vmware-cis/vcf/vcf-9-0-and-later/9-1/release-notes/async-releases/vcf-operations-for-integrations-91-release-notes.html?ref=mohammadsiddiqui.com).

Log management, now in the same place as metrics 

If you're still treating logs and metrics as separate products with separate content libraries, that gap closed. During an incident it means one place to look rather than two, which is worth more than it sounds at 2am. Legacy content packs can be converted rather than rewritten.

The AI Assistant in the Operations console 

Arrived in 9.1.1\. Day 2 troubleshooting and diagnostics, and the part that matters for regulated customers is that you can point it at a model you host yourself rather than sending operational data out. [Detail here](https://blogs.vmware.com/cloud-foundation/2026/09/03/new-ai-and-kubernetes-private-cloud-operations-capabilities-in-vmware-cloud-foundation-9-1-1/?ref=mohammadsiddiqui.com).

OpenTelemetry observability for VKS 

Also 9.1.1\. If you run VKS and have ever tried to troubleshoot something that appeared and vanished inside ninety seconds, this is the gap it fills.

## Lifecycle and patching

Live Patch, if your clusters are image-managed 

This is the one I'd check first. Live Patch is the fast route for security patching, and it requires image-managed clusters. Plenty of estates upgraded and left clusters on baselines, which means the capability is entitled, present, and unavailable. Converting is not difficult. It's just never urgent until the week it is.

Certificate automation 

Auto-renewal exists and is off in a lot of places. Worth knowing it fires 60 days before expiry and cannot be enabled for a certificate already inside that window without renewing by hand first. Management and instance certificates configure separately. [Documentation here](https://techdocs.broadcom.com/us/en/vmware-cis/vcf/vcf-9-0-and-later/9-1/fleet-management/certificate-management-9-0/?ref=mohammadsiddiqui.com).

TLS profiles 

Set, apply and audit TLS configuration across the fleet rather than host by host. Turns crypto configuration from a per-host setting into a managed property, which is also the groundwork for post-quantum work later.

Salt for drift remediation 

Continuous compliance monitoring and drift correction. Most people who have it are not using it. Start in detection mode and look at what it finds before you let it change anything.

## Security you may not have enabled

Post-quantum key exchange in Avi 

Avi Load Balancer already supports hybrid post-quantum key exchange in TLS. If you have public-facing services behind Avi, you can protect them against harvest-now-decrypt-later today, with no waiting for standards or hardware. [Configuration guide](https://techdocs.broadcom.com/us/en/vmware-security-load-balancing/avi-load-balancer/avi-load-balancer/31-2/vmware-avi-load-balancer-configuration-guide/security/ssl-tls-profile/ssl-profile-templates/post-quantum-cryptography.html?ref=mohammadsiddiqui.com). This is the most actionable security item on the whole list and hardly anyone has switched it on.

The Security Configuration Guide and STIG readiness content 

Free, published, and more thorough than most internally written hardening standards. If your security baseline was written for 6.7 and patched since, it is worth reading the current guide end to end. [Here](https://brcm.tech/vcf-scg?ref=mohammadsiddiqui.com).

vDefend capabilities you already licensed 

Distributed firewall, IDS/IPS, and in 9.1.1 the agentic discovery features including shadow AI detection. Worth running discovery even if you do nothing else with it, because the inventory of what is talking to what usually contains surprises.

## Platform capability sitting idle

VCF Automation, if you have it and are not using it 

A lot of estates have the entitlement and run everything through tickets anyway. That is the largest single gap between what people pay for and what they use. It is also the hardest to close, because it is an operating model change rather than a deployment. Worth a separate conversation rather than an afternoon.

Data Services Manager 

Database provisioning as a service. Databases provisioned through DSM get monitoring automatically with no manual configuration, surfaced in a Data Services view. If you have DSM and are hand-building databases, that is effort you are choosing to spend.

GitOps with Argo CD 

Native in VCF Automation from 9.1.1, Tech Preview. Worth knowing about and understanding the constraints, one instance per hosting namespace scoped to a single region, but not worth building on yet. [Detail here](https://blogs.vmware.com/cloud-foundation/2026/09/03/from-bottleneck-to-breakthrough-centralizing-gitops-at-enterprise-scale-with-vcf-9-1-1/?ref=mohammadsiddiqui.com).

## How to actually do the audit

An afternoon, not a project.

Pull your current entitlement from your licensing record, not from memory or from what somebody said at renewal List what is actually deployed and configured, which is a different list Mark every line that is entitled but not deployed For each gap, estimate effort in hours or days. Most will be hours Rank by effort against operational pain, and do the cheap ones this month Put the remainder on one slide and keep it current

Why the slide matters

Entitled but not deployed is the clearest budget conversation you will ever have. It costs nothing to close, it shows the platform investment working, and it makes the case for the next phase far better than a feature list does. Keep it to one page and update it quarterly.

Want a score rather than a reading list?

I built a [short self-assessment](https://www.mohammadsiddiqui.com/how-much-of-your-platform-are-you-actually-using/) covering the same ground. Fifteen questions, about four minutes, and it scores your estate across five areas with what I would do next in each. Nothing is sent anywhere, it all runs in your browser.

## Sources

- [VCF 9.1 and VVF 9.1 feature comparison](https://www.vmware.com/docs/vmware-cloud-foundation-9-1-feature-comparison-and-upgrade-paths?ref=mohammadsiddiqui.com): the edition boundaries for every capability above.
- [VCF Operations for Integrations 9.1 release notes](https://techdocs.broadcom.com/us/en/vmware-cis/vcf/vcf-9-0-and-later/9-1/release-notes/async-releases/vcf-operations-for-integrations-91-release-notes.html?ref=mohammadsiddiqui.com): log convergence and management pack changes.
- [New AI and Kubernetes operations capabilities in VCF 9.1.1](https://blogs.vmware.com/cloud-foundation/2026/09/03/new-ai-and-kubernetes-private-cloud-operations-capabilities-in-vmware-cloud-foundation-9-1-1/?ref=mohammadsiddiqui.com).
- [VCF Marketplace](https://vcf.broadcom.com/vsc/?ref=mohammadsiddiqui.com): the management packs themselves.
- [Certificate management](https://techdocs.broadcom.com/us/en/vmware-cis/vcf/vcf-9-0-and-later/9-1/fleet-management/certificate-management-9-0/?ref=mohammadsiddiqui.com): auto-renewal behaviour and the 60-day rule.
- [Avi post-quantum cryptography configuration](https://techdocs.broadcom.com/us/en/vmware-security-load-balancing/avi-load-balancer/avi-load-balancer/31-2/vmware-avi-load-balancer-configuration-guide/security/ssl-tls-profile/ssl-profile-templates/post-quantum-cryptography.html?ref=mohammadsiddiqui.com).
- [VCF Security Configuration Guide](https://brcm.tech/vcf-scg?ref=mohammadsiddiqui.com).
- [Centralizing GitOps with VCF 9.1.1](https://blogs.vmware.com/cloud-foundation/2026/09/03/from-bottleneck-to-breakthrough-centralizing-gitops-at-enterprise-scale-with-vcf-9-1-1/?ref=mohammadsiddiqui.com).

*Entitlements vary by agreement and change at renewal. Check yours rather than assuming anything here applies.*

*Views expressed here are my own.*