Rows of servers in an enterprise data center
Guide · Oracle · Virtualization

Oracle Licensing on VMware. Where the cluster counts.

Oracle treats VMware as soft partitioning, so it counts every core a database could ever reach rather than the cores it runs on today. What the policy says, what it is worth in a negotiation, and the cluster design that removes the argument.

Contact Us →Read the analysis Oracle Practice
500+Enterprise clients
$2B+Under advisory
Industry Recognized
500+ Enterprise Clients
$2B+ Under Advisory
11 Vendor Practices
100% Buyer Side Independent

Oracle counts every core an Oracle database could reach in your VMware estate, not the cores it runs on. That one rule produces most of the cost surprise on virtualized Oracle, and it is the reason a two core database can carry a claim against a hundred cores.

VMware is soft partitioning in Oracle's view. The database does not have to run on a host for Oracle to count that host. The ability to migrate to it is enough.

This guide walks the counting rule, why the boundary moved as vSphere matured, which containment moves survive an audit, what the partitioning policy is and is not, and how the arithmetic changes in cloud. Read it with the Oracle Database licensing guide.

Key takeaways

  • Oracle counts reach, not use. The licensable boundary is every physical core a database virtual machine could be moved to, which is why a shared cluster is a shared bill.
  • VMware is named as soft partitioning in Oracle's own policy. The document lists the accepted hard partitioning technologies, and VMware is not among them.
  • That policy is not a contract term, and it says so. Oracle's partitioning document states it is for educational purposes only and may not be incorporated into any contract.
  • DRS host affinity rules are not a licensing boundary. Oracle rejects them regularly because an administrator can change them in a minute, and audit findings are built on what is possible.
  • The gap between pinned hosts and reachable pool runs 3 to 8 times on the estates we review, and a single flat vCenter is usually the reason.
  • The answer is architectural, not argumentative. A dedicated cluster in its own vCenter with capped sockets removes the dispute rather than winning it.
  • Cloud swaps the argument for arithmetic. In Authorized Cloud Environments the count is by vCPU and the core factor table does not apply.
Try Vera AI · free 30 day trial
Vera prices your VMware estate three ways before Broadcom does.
  • RVTools in, core sizing out: three pricing scenarios across discount bands
  • Your quote benchmarked against real closed Broadcom deals
  • Exit and alternative scenarios priced so you negotiate with a credible walkaway
Try Vera AI free →30 day free trial · no card needed

How does Oracle count licenses on VMware?

By counting every physical core where an Oracle database could run, not where it runs today. Because VMware allows live migration, Oracle treats the whole reachable estate as licensable.

Oracle sets out the technologies it accepts in its server partitioning policy. Understanding exactly what that document says, and what status it has, is the foundation of any defensible position.

Soft partitioning versus hard partitioning

Hard partitioning lets you license a subset of a server. Soft partitioning does not. Oracle's policy names both categories explicitly, and the lists are short.

  • Accepted as hard partitioning. Physical domains, capped Solaris Zones, IBM LPAR and capped micro partitions, capped vPar, nPar, capped Integrity Virtual Machines, Secure Resource Partitions and Fujitsu PPAR.
  • Named as soft partitioning. Solaris 9 Resource Containers, AIX Workload Manager, HP Process Resource Manager, affinity management, Oracle VM and VMware.
  • The stated rule. Soft partitioning is not permitted as a means to determine or limit the number of licenses required for a given server or cluster of servers.

Note that Oracle's own VM product sits in the soft list unless it is configured for hard partitioning. The category is about capping, not about the vendor logo.

Why vMotion widens the count

Because the licensable boundary is defined by where a workload can go, and vMotion is exactly a statement about where a workload can go. Every host in scope for live migration is a host in scope for licensing.

That makes three infrastructure decisions into licensing decisions, whether or not anyone framed them that way at the time.

  1. Cluster membership. Which ESXi hosts sit in the same cluster as the database hosts.
  2. Shared storage. Which datastores are visible to which hosts, because shared storage historically defined the migration reach.
  3. vCenter and management scope. Whether one management domain spans clusters that have no operational reason to be joined.

Apply the multipliers from the Processor Core Factor Table to that full pool, not to the hosts your database happens to sit on this morning.

Three questions that locate your real boundary

Ask them in this order, and answer them with configuration exports rather than opinions.

  • If an administrator with normal privileges wanted to move this database to that host right now, could they?
  • Would anything technical stop them, or only a rule, a policy or a habit?
  • Could you prove to a third party, from records dated before today, that it has never happened?

Any host where the first answer is yes belongs in your count until you change the architecture. That is the uncomfortable part, and it is also the part you can fix.

Is Oracle's partitioning policy part of your contract?

Almost certainly not, and Oracle's document says as much on its own face. The partitioning policy states that it is for educational purposes only, that it provides guidelines regarding Oracle's policies, and that it may not be incorporated into any contract.

The version most buyers are shown carries policy guidance dated 14 February 2022. It is a statement of how Oracle intends to interpret licensing, not a term you signed.

What that actually buys you

Leverage, not immunity. A finding built on a document Oracle itself describes as non contractual is a weaker finding than one built on your ordering document, and it should be priced that way in a settlement.

Where each rule actually comes from

RuleSourceStatus
You must license all processors on which the program is installed and runningOrdering document and master agreementContractual
Core factor multipliers by processor modelProcessor Core Factor Table, referenced in the agreementContractual by reference
VMware is soft partitioning and cannot limit the countPartitioning policy documentPolicy, stated as not contractual
The reachable cluster defines the licensable poolOracle interpretation of the abovePosition, not policy text
vCPU conversion in Authorized Cloud EnvironmentsCloud licensing policy documentPolicy, stated as not contractual

The practical reading is straightforward. Argue the status of the policy in a negotiation, and remove the exposure with architecture. Doing only the first leaves you renting the argument every three years.

Which VMware versions widen Oracle's licensing claim?

Every release that extended live migration extended the boundary Oracle argues for. Oracle audit teams cite the version precisely because it supports the widest defensible reach.

The version escalation

  • vSphere 5.1. Migration between hosts without shared storage removed the storage boundary that many designs relied on.
  • vSphere 6.0. Migration across vCenter instances and across long distances widened the pool again.
  • vSphere 7 and 8. Oracle argues the reachable set is every cluster a virtual machine could be moved to within the management estate.

What the version means for your defense

The version is not the problem, and downgrading is not the answer. Shared scope is the problem, and a modern estate with one flat vCenter simply gives Oracle the largest possible claim.

The fix is separation. If the Oracle estate cannot technically reach the rest of the estate, the vSphere version stops mattering.

Put your own numbers on this. The free Oracle calculator prices your processor vs Named User Plus position, VMware cluster exposure, Java SE employee tiers, and the 22 percent support line, then hands you a two page executive summary you can forward to your CFO. No account, no sales call. Run the Oracle calculator →

How do you contain Oracle on VMware?

By cutting the reachable pool down to a boundary that exists in hardware and configuration, not in policy documents. Only physical and management separation survives contact with an audit.

Containment that holds

  • Dedicated cluster. Oracle workloads run on their own ESXi hosts, with no cores shared with anything else.
  • Separate vCenter and SSO domain. The Oracle estate is managed independently, so cross vCenter migration is not available.
  • Separate storage presentation. Datastores holding Oracle virtual machines are presented only to the Oracle hosts.
  • Capped sockets. The cluster is sized to the licenses you hold, and expansion goes through a license check.
  • Physical isolation. Where the exposure is large, separate hardware ends the discussion entirely.

Cluster design as a licensing control

Treat the Oracle cluster as a licensed appliance with a fixed core budget. That reframing is what turns a licensing problem into an infrastructure standard your platform team can actually own.

Three design rules make it work in practice. Size the cluster to entitlement rather than to peak demand. Keep failover capacity inside the licensed boundary. Make any host addition a change that requires a license check before it is racked.

Done properly, the containment holds without anybody remembering a rule. That is the test. A boundary that depends on discipline is a boundary that will fail during an incident at two in the morning.

Containment approaches and Oracle's stance

ApproachOracle stanceWhat Oracle counts
Shared cluster, host affinity rules onlyRejectedEvery core in the management estate
Dedicated Oracle cluster inside a shared vCenterContestedArgued up to the full vCenter
Dedicated cluster, separate vCenter and SSO domainStrongest soft boundaryCores in the isolated estate
Physical isolation, capped socketsAcceptedThe capped sockets only
Approved hard partitioning technologyAccepted by policyThe capped partition only

The evidence pack you need before anyone asks

Containment you cannot evidence is containment you do not have. Build the pack while the estate is calm, and date everything.

  1. Cluster and host inventory with processor model, socket and core counts.
  2. vCenter topology showing the Oracle estate and its management boundary.
  3. Storage presentation maps for every datastore holding an Oracle virtual machine.
  4. Change records for the isolation project, with dates and approvals.
  5. The standard that governs host additions, and evidence it has been followed.
Cover of the Redress Compliance Oracle white paper

White Paper · Oracle

Oracle & VMware Licensing

Bound Oracle licensing on VMware. Read it free.

Read the white paper

Should you move Oracle off VMware to cloud or OCI?

Consider it, because cloud replaces an argument about reach with a published conversion. Oracle's cloud licensing policy names Amazon EC2 and RDS, Microsoft Azure and Google Cloud Platform as Authorized Cloud Environments.

Predictable is not the same as cheap. The core factor table does not apply in those environments, so a processor with a favorable factor loses that advantage on migration.

The counting math when you bring your own license

  • Authorized clouds with hyperthreading enabled. Two vCPUs count as one processor license.
  • Authorized clouds without hyperthreading. One vCPU counts as one processor license.
  • Core factor. Not applicable in Authorized Cloud Environments, which is where the migration surprise usually comes from.
  • Oracle Cloud Infrastructure. Counted on its own terms, and some workloads license better as a managed service. See the Oracle Database service options.
  • List anchor. Validate every quote against the Oracle Technology Price List before you compare scenarios.

Run the numbers both ways before committing. Our Oracle licensing in cloud environments guide sets out the full rules, including the Named User Plus minimums that apply there.

Where the common advice on Oracle and VMware licensing is wrong

The standard advice from many infrastructure teams is that DRS host affinity rules will pin Oracle to a few hosts and cap the license count. We disagree. In roughly 30 of the 50 virtualized estates we reviewed across 2024 and 2025, Oracle rejected affinity rules in the audit because the VM could still be moved by an administrator, so the reachable pool stood. The buyer side move is to build a physically separate Oracle cluster on capped sockets, in its own vCenter, and to treat configuration rules as convenience, not as a licensing boundary that Oracle will honor.

A dedicated rack of database hosts separated from the main cluster
The defensible boundary is hardware you can point to, not a rule inside vSphere that an administrator can change in a minute.
50
VMware estates reviewed
3 to 8x
Cluster core counting gap
60%
Median claim reduction

Source: Redress Compliance advisory engagement file, 2024 to 2025.

The Oracle number on a VMware estate is the size of the cluster Oracle can reach, not the size of the workload you run. Shrink the reach and you shrink the bill.

How do failover and disaster recovery hosts count?

Under a narrow published allowance that most virtualized designs quietly exceed. Oracle's data recovery licensing policy permits running a licensed program on an unlicensed spare computer in a failover environment for up to a total of ten separate 24 hour periods in a calendar year.

The allowance is conditional. It applies where machines are arranged in a cluster sharing one logical disk array in a single data center. Once failover has exceeded those ten periods, the policy states the failover node must be licensed.

Where virtualized estates break the rule without noticing

  • Standby databases. In mirroring and standby deployments all installed or running Oracle programs must be licensed under standard policies, and the metrics and options must match production.
  • Automated host maintenance. Routine evacuation of hosts for patching moves database workloads far more often than ten days a year, and nobody is counting.
  • Backup testing. Testing physical backup copies on an unlicensed server is limited to four times a year, not exceeding two days per test.
  • Recovery hosts inside the shared cluster. A recovery target that sits in the general estate pulls that whole estate back into the reachable pool.

Two practical consequences follow. Keep failover capacity inside the licensed Oracle boundary rather than borrowing hosts from the general cluster. And log failover events, because the ten day allowance is only useful if you can evidence that you stayed inside it.

What does containment actually cost?

Less than one year of the exposure it removes, in every case we have modeled. That is the comparison to put in front of a CFO, and it is the reason isolation projects get funded when they are framed as license avoidance rather than as infrastructure work.

The four cost lines

  • Hardware. Dedicated hosts, sized to entitlement with failover capacity inside the boundary.
  • Management separation. A second vCenter and the operational work to run it.
  • Migration effort. Moving database virtual machines with tested rollback, usually the largest line.
  • Ongoing governance. The change control that keeps the boundary intact after the project team leaves.

How to build the business case

Price three scenarios side by side and let the numbers argue. Status quo with the reachable pool licensed in full, containment with a dedicated and isolated cluster, and migration to an authorized cloud with the vCPU conversion applied.

Include five years of support at 22 percent with annual escalation in every scenario. Support is where the difference compounds, and a comparison that shows only license cost will understate the case for containment.

What should a buyer do next?

Sequence the measurement before the isolation, and the isolation before the renewal or audit response.

  1. Map the reach. List every host a database virtual machine can be migrated to today.
  2. Find the shared pools. Identify clusters that share a vCenter, an SSO domain or storage presentation.
  3. Count both ways. Pinned hosts against the full reachable pool, with the core factor applied to each.
  4. Price the gap. Convert the difference into licenses and five years of support, so the exposure has a number.
  5. Design the island. A dedicated Oracle cluster sized to entitlement, with failover inside the boundary.
  6. Split the vCenter. Move the Oracle estate into its own management domain.
  7. Cap the sockets and put host additions behind a license check.
  8. Build the evidence pack and date it, before anyone asks for it.
  9. Model the cloud path against staying, using the vCPU rules rather than core counts.
  10. Open the renewal on your contained position, not on Oracle's reachable claim.
Need help? Try our AI agents. Ask the Oracle licensing AI agent → Scoped to one vendor and one problem. Runs in your browser.
Cover of Oracle Database Options and Management Packs Licensing from Redress Compliance

White Paper · Advisory

Oracle Database Options & Management Packs Licensing

The separately licensed options and packs that ship enabled by default, trigger on one click, and drive most Oracle audit findings. How feature usage is detected, prevented and defended. Read it free.

Read the white paper

Frequently asked questions

Does Oracle count all VMware hosts or only the ones running the database?

Oracle counts every host a database virtual machine can reach through live migration, not only the hosts it runs on. VMware is treated as soft partitioning, so the reachable pool is the licensable boundary until you separate the estate physically and in management scope.

Is VMware approved for Oracle hard partitioning?

No. Oracle's partitioning policy names VMware in its soft partitioning list. The approved hard partitioning methods are physical domains, capped Solaris Zones, IBM LPAR and capped micro partitions, capped vPar, nPar, capped Integrity Virtual Machines and Fujitsu PPAR.

Do DRS host affinity rules limit Oracle licensing?

Not reliably, and you should not plan around them. Oracle commonly rejects affinity rules because an administrator can change them without a hardware change, and audit findings are built on what is technically possible. Only physical separation or a separate management domain holds up.

Is Oracle's partitioning policy legally binding on us?

The document states that it is for educational purposes only and may not be incorporated into any contract. That gives you a real argument where the policy is not referenced in your ordering document. Treat it as negotiating leverage rather than as a defense you can rely on alone.

How much can the VMware counting gap cost?

The difference between pinned hosts and the full reachable pool commonly runs 3 to 8 times on the estates we review. On a large shared management estate that gap reaches seven figures once five years of support is included, which is why isolation projects usually pay back inside a year.

Does a separate vCenter reduce the Oracle count?

Yes, materially. Isolating the Oracle estate in its own vCenter and SSO domain removes cross vCenter migration and cuts the reachable pool to that estate. It is the strongest boundary available short of fully separate hardware.

How does Oracle licensing change on AWS or Azure?

The unit changes from reachable cores to vCPUs. Two vCPUs count as one processor license where hyperthreading is enabled, one vCPU where it is not, and the Processor Core Factor Table does not apply. That removes the reachability argument but can raise the count on hardware with a favorable core factor.

Should we tell Oracle about our containment design?

Yes, in writing, at the right moment. A documented and dated containment design presented during scope discussion is far more effective than the same design produced after a finding. Ideally the acceptance is recorded in a contract amendment at your next purchase or renewal.

How does Redress engage on Oracle and VMware?

By mapping the reachable pool, designing the contained estate with your platform team, and running the renewal or audit response on the measured position. We do not resell Oracle or VMware and we do not implement either.

The work runs inside the Vendor Shield subscription, the Renewal Program, and the Benchmark Program, and it connects directly to the Oracle audit defense guide when a notice has already arrived.

Read the related Oracle services page, the Oracle knowledge hub, the benchmarking page, and the contact page.

Run the Oracle Java license calculator against your virtualized estate in under five minutes.
Open the Oracle Java License Calculator →
White Paper · Oracle

Oracle & VMware Licensing

The buyer side moves that keep your Oracle estate honest at renewal.

Independent. Buyer side. Built for Oracle customers running the next renewal cycle.

Oracle & VMware Licensing

Open the white paper in your browser. Corporate email only.

Open the Paper →
Pass it on

Know someone facing this exact decision?

Send this to whoever owns the renewal, the audit response, or the budget. It takes two clicks and it saves them a quarter of guessing.

Share on LinkedInShare by email
Editorial photograph of an enterprise office

Your renewal calendar is your leverage.

Renewal in twelve months. Audit notice in the inbox. RFP on the desk. We start where you are.

Oracle virtualization intelligence, monthly.

VMware core counting rules, vMotion scope, containment moves, OCI and BYOL math, and audit defense intelligence from every Oracle engagement we run on the buyer side.