Contents
Key takeawaysHow Oracle counts on VMwareIs the policy contractual?vSphere versions and reachWhat the gap costsContaining Oracle on VMwareWhat we saw in 2024 and 2025Failover and DR hostsMoving to cloud or OCIWhat Oracle will sayCost and business caseHow Redress helpsWhat to do nextFAQOracle licenses every physical core a database virtual machine could be moved to, so a shared VMware cluster becomes a shared bill. A dedicated, separately managed Oracle cluster sized to your licenses is the containment that holds up in an audit.
- Oracle counts reach. The licensable boundary is every physical core a database virtual machine could migrate to, whatever it runs on today.
- VMware is on the soft partitioning list. Oracle's partitioning policy names the accepted hard partitioning technologies, and VMware is not among them.
- That policy says it is not a contract term. The document calls itself educational and excludes itself from your contract, which weakens any finding built on it.
- Affinity rules do not cap the count. Oracle regularly rejects DRS host affinity rules because an administrator can change them in a minute.
- The gap is usually 3 to 8 times. That is the spread between pinned hosts and the reachable pool on the environments we review, and one flat vCenter is usually the cause.
- Fix it in the architecture. A dedicated cluster in its own vCenter, with capped sockets and failover inside the boundary, removes the dispute instead of arguing it.
- Cloud swaps reach for a conversion. In Authorized Cloud Environments Oracle counts vCPUs and the core factor table does not apply.
How does Oracle count licenses on VMware?
Oracle counts every physical core an Oracle database could run on, including cores it has never touched. Because vSphere can move a running virtual machine between hosts, Oracle treats the whole reachable pool of hosts as licensable. That is why a two core database can carry a claim against a hundred cores.
The database does not have to run on a host for Oracle to count that host. The technical ability to migrate there is enough. This page covers the counting rule, how vSphere releases widened it, which containment designs survive an audit and how the numbers change in cloud. Read it alongside our Oracle Database licensing guide.
Soft partitioning versus hard partitioning
Hard partitioning allows you to license a subset of a server's processors. Soft partitioning does not. Oracle's server partitioning policy names both categories, and both lists are short.
- Accepted as hard partitioning. Physical domains, capped Solaris Zones, IBM LPAR and capped micro partitions, capped vPar, nPar, capped Integrity Virtual Machines, capped Secure Resource Partitions and Fujitsu PPAR.
- Named as soft partitioning. Solaris 9 Resource Containers, AIX Workload Manager, HP Process Resource Manager, affinity management, Oracle VM and VMware.
- The rule Oracle states. Soft partitioning is not permitted as a means to determine or limit the number of licenses required for a given server or cluster of servers.
Oracle's own virtualization sits in the soft list too. Oracle VM Server and Oracle Linux KVM count as hard partitioning only when they are configured the way Oracle's supporting documents describe, with CPUs pinned to the guest. The category turns on capping, whoever made the hypervisor. Our note on KVM and OLVM core counting covers that route.
Why vMotion widens the count
The licensable boundary is defined by where a workload can go, and vMotion is a statement about exactly that. Every host in scope for live migration is a host in scope for licensing. As a result, three infrastructure decisions became licensing decisions, usually without anyone treating them that way at the time.
- Cluster membership. Which ESXi hosts sit in the same cluster as the database hosts.
- Shared storage. Which datastores are visible to which hosts, because shared storage historically defined how far a virtual machine could migrate.
- vCenter and management scope. Whether one management domain spans clusters that have no operational reason to be joined.
Apply the multipliers from the Processor Core Factor Table to that full pool. The hosts your database happens to sit on this morning are only part of it. For current Intel Xeon and AMD EPYC processors the factor is 0.5, so every two physical cores need one processor license. The core factor guide lists the other chip families.
Three questions that locate your real boundary
Ask them in this order, and answer them from configuration exports. Opinions from the platform team do not count as evidence.
- If an administrator with normal privileges wanted to move this database to that host right now, could they?
- Would anything technical stop them, or only a rule, a policy or a habit?
- Could you prove to a third party, from records dated before today, that it has never happened?
Any host where the first answer is yes belongs in your count until you change the architecture. That is the uncomfortable finding, and it is also the one you can fix.
The VMware Estate After the Repackaging
Is Oracle's partitioning policy part of your contract?
Almost certainly not, and the document says so on its face. Oracle's partitioning policy states that it is for educational purposes only, that it provides guidelines regarding Oracle's policies, and that it may not be incorporated into any contract.
The current version carries policy guidance dated February 14, 2022. It records how Oracle intends to interpret its licenses. You did not sign it, unless your ordering document references it, so read your ordering documents before you rely on the point. Our partitioning policy explainer goes through the text line by line.
| Rule | Source | Status |
|---|---|---|
| You must license all processors on which the program is installed and running | Ordering document and master agreement | Contractual |
| Core factor multipliers by processor model | Processor Core Factor Table, referenced in the agreement | Contractual by reference |
| VMware is soft partitioning and cannot limit the count | Partitioning policy document | Policy, stated as not contractual |
| The reachable cluster defines the licensable pool | Oracle's interpretation of the rows above | Oracle's position, absent from the policy text |
| vCPU conversion in Authorized Cloud Environments | Cloud licensing policy document | Policy, stated as not contractual |
What the policy's status gets you in a negotiation
It gives you bargaining room in a settlement, though it does not make the finding disappear. A finding built on a document Oracle itself calls non contractual is weaker than one built on your ordering document, and a settlement should be priced to reflect that.
Use the point in the negotiation and remove the exposure with architecture. Customers who only argue the policy end up having the same argument again at the next audit, roughly every three years.
Which VMware versions widen Oracle's licensing claim?
Every vSphere release that extended live migration extended the boundary Oracle argues for. Oracle's audit teams cite the version because it supports the widest reach they can claim.
How the reach grew release by release
- vSphere 5.1. Migration between hosts without shared storage removed the storage boundary many designs relied on.
- vSphere 6.0. Migration across vCenter instances and over long distances widened the pool again.
- vSphere 7 and 8. Oracle argues the reachable set is every cluster a virtual machine could be moved to within your management domain. Since vSphere 7.0 Update 1c, Advanced Cross vCenter vMotion allows an administrator to move a running virtual machine from the vSphere Client to a vCenter in a different single sign on domain, with no Enhanced Linked Mode required.
What the version means for your defense
Downgrading is no answer, because the version is not the cause. Shared management scope is, and a modern environment with one flat vCenter hands Oracle the largest possible claim.
That feature needs only two things: vMotion network connectivity between the source and destination hosts, and credentials for the destination vCenter. So a separate vCenter works as a boundary only when the vMotion networks and administrator credentials are separated too. If the Oracle environment cannot technically reach anything else, the vSphere version stops mattering.
How much does the VMware counting gap cost?
It usually costs several times the licenses you bought for the hosts the database runs on. On the environments we review, the gap between the hosts a database is pinned to and the full reachable pool runs 3 to 8 times. A worked example shows how quickly that becomes money.
Say four Enterprise Edition virtual machines are held by DRS rules on 2 hosts, each with two 12 core Intel Xeon processors (24 cores per host). Those hosts sit in a 6 host cluster inside a vCenter that manages 16 hosts. Prices use the $47,500 Enterprise Edition processor list price, with support at 22 percent.
| What you count | Physical cores | Licenses at 0.5 factor | License at list | Annual support at 22 percent |
|---|---|---|---|---|
| The 2 pinned hosts | 48 | 24 | $1,140,000 | $250,800 |
| The 6 host cluster | 144 | 72 | $3,420,000 | $752,400 |
| All 16 hosts in the vCenter | 384 | 192 | $9,120,000 | $2,006,400 |
The cluster count is 3 times the pinned count, and the vCenter count is 8 times. The gap between the first and last rows is 168 licenses: $7,980,000 at list, plus $1,755,600 a year in support. Each Enterprise Edition option in use, such as Diagnostics Pack, adds its own per processor price across that gap.
Over five years, support alone grows from $1,254,000 on the pinned hosts to $10,032,000 on the full vCenter, before any annual escalation. Settlements rarely land at list, but this is the scale of number Oracle opens with.
How do you contain Oracle on VMware?
Cut the reachable pool down to a boundary that exists in hardware and configuration. Policy documents and runbooks do not create one. Only physical and management separation holds up when an auditor tests it.
Containment that holds
- Dedicated cluster. Oracle workloads run on their own ESXi hosts, sharing no cores with anything else.
- Separate vCenter and SSO domain. The Oracle environment is managed on its own, so cross vCenter migration is not available from the general platform.
- Separate vMotion network and credentials. No network path and no shared administrator account that would let a cross vCenter move run anyway.
- Separate storage presentation. Datastores holding Oracle virtual machines are presented only to the Oracle hosts.
- Capped sockets. The cluster is sized to the licenses you hold, and any expansion goes through a license check.
- Physical isolation. Where the exposure is large, separate hardware ends the discussion.
Design the cluster as a licensed appliance
Give the Oracle cluster a fixed core budget, the way you would treat an appliance. This turns a licensing problem into an infrastructure standard your platform team can own. Three design rules make it work: size to entitlement instead of peak demand, keep failover capacity inside the licensed boundary, and require a license check before any new host is racked.
In the worked example, the same 24 licenses cover 4 hosts with one 12 core processor each. That is 48 cores, and any 3 hosts can carry the load while the fourth is patched. The boundary should hold without anyone remembering a rule, because a boundary that depends on discipline fails during an incident at two in the morning.
| Approach | Oracle stance | What Oracle counts |
|---|---|---|
| Shared cluster, host affinity rules only | Rejected | Every core in the management domain |
| Dedicated Oracle cluster inside a shared vCenter | Contested | Argued up to the full vCenter |
| Dedicated cluster, separate vCenter and SSO domain | Strongest soft boundary | Cores in the isolated environment |
| Physical isolation, capped sockets | Accepted | The capped sockets only |
| Approved hard partitioning technology | Accepted by policy | The capped partition only |
Our design note on the dedicated VMware cluster for Oracle covers host sizing and change control in more detail, and the Oracle and VMware licensing white paper sets out the full containment approach.
How to check your own position
Pull the data your platform team already has before Oracle asks for it. These sources show what is reachable today:
- RVTools export. The vHost, vCluster and vInfo tabs list every host, its CPU model, sockets and cores, and which cluster each virtual machine sits in.
- PowerCLI queries. Get-Cluster, Get-VMHost and Get-DrsVMHostRule show cluster membership and affinity rules. Get-VMHostNetworkAdapter with the VMKernel parameter lists each VMkernel adapter and whether vMotion is enabled on it.
- Datastore mounts. For each datastore holding an Oracle virtual machine, list the hosts it is mounted on.
- vCenter linking. Check whether the Oracle vCenter is in Enhanced Linked Mode or the same SSO domain as any other vCenter.
Oracle's audit team will ask for this same host data, usually through its own server worksheet. Fill it in yourself first, from the same exports, so you see the count before Oracle does.
The evidence pack you need before anyone asks
If you cannot prove containment, Oracle will treat it as absent. Build the pack while nothing is under dispute, and date everything.
- Cluster and host inventory with processor model, socket and core counts.
- vCenter topology showing the Oracle environment and its management boundary.
- Storage presentation maps for every datastore holding an Oracle virtual machine.
- Change records for the isolation project, with dates and approvals.
- The standard that governs host additions, and evidence it has been followed.
What have we seen in Oracle on VMware audits in 2024 and 2025?
The audit gap was almost never about the running workload. Across roughly 40 to 55 virtualized Oracle environments Fredrik Filipsson reviewed or defended between 2024 and 2025, the exposure came from reachable hosts that no one had isolated. Three patterns came up again and again.
- Licensed on pinned hosts, counted on the vCenter. Customers had bought licenses for the hosts running Oracle, while Oracle counted every core in the vCenter. That is the gap priced in the worked example above.
- Affinity rules treated as containment. DRS host affinity rules were presented as the boundary, and Oracle rejected them in the audit.
- One shared vCenter. A single vCenter pulled unrelated clusters into one reachable pool and inflated the claim further.
Across the roughly 50 VMware environments in that review set, the median reduction we achieved against Oracle's claimed count was 60 percent.
Why we do not rely on DRS affinity rules to cap the count
Many infrastructure teams advise that DRS host affinity rules will pin Oracle to a few hosts and cap the license count. We disagree. In roughly 30 of the 50 environments we reviewed across 2024 and 2025, Oracle rejected affinity rules in the audit, because an administrator could still move the virtual machine in a minute. The reachable pool stood.
Build a physically separate Oracle cluster on capped sockets, in its own vCenter, and treat configuration rules as an operational convenience. Oracle will not honor them as a licensing boundary. Our guide to soft partitioning audit defense covers how these findings are argued.
On a VMware environment, the Oracle number is set by the size of the cluster Oracle can reach. Shrink the reach and you shrink the bill.
How do failover and disaster recovery hosts count?
They count under a narrow published allowance, and most virtualized designs exceed it without anyone tracking it. Oracle's data recovery licensing policy permits running a licensed program on an unlicensed spare computer in a failover environment for up to a total of ten separate 24 hour periods in a calendar year.
The allowance is conditional. It applies where machines are arranged in a cluster sharing one logical disk array in a single data center. Once failover has exceeded those ten periods, the policy states that the failover node must be licensed.
Where virtualized environments break the rule without noticing
- Standby databases. In mirroring and standby deployments, all installed or running Oracle programs must be licensed under standard policies, and the metrics and options must match production.
- Automated host maintenance. Routine evacuation of hosts for patching shifts database workloads far more often than ten days a year, and no one is counting.
- Backup testing. Testing physical backup copies on an unlicensed server is limited to four times a year, with no test longer than two days.
- Recovery hosts inside the shared cluster. A recovery target that sits in the general cluster pulls that whole cluster back into the reachable pool.
Two practical consequences follow. Keep failover capacity inside the licensed Oracle boundary instead of borrowing hosts from the general cluster. And log failover events, because the ten day allowance only helps if you can show you stayed inside it.
Should you move Oracle off VMware to cloud or OCI?
Consider it, because cloud replaces an argument about reach with a published conversion. Oracle's cloud licensing policy names Amazon EC2 and RDS, Microsoft Azure and Google Cloud Platform as Authorized Cloud Environments.
A predictable count is not always a cheaper one. The core factor table does not apply in those environments, so a processor with a favorable factor loses that advantage when you migrate.
How the count works when you bring your own license
- Authorized clouds with hyperthreading enabled. Two vCPUs count as one processor license.
- Authorized clouds without hyperthreading. One vCPU counts as one processor license.
- Core factor. Not applicable in Authorized Cloud Environments, which is where the migration surprise usually comes from.
- Standard Edition 2. Up to 4 vCPUs count as one socket, larger instances count one socket per 4 vCPUs rounded up, and the instance may not exceed 8 vCPUs. Named User Plus needs at least 10 users per 8 vCPUs.
- Oracle Cloud Infrastructure. Counted on its own terms, and some workloads license better as a managed service. See the Oracle Database service options.
- List prices. Check every quote against the Oracle Technology Price List before you compare scenarios.
Go back to the worked example. On Intel hosts, one physical core costs half a license. In an authorized cloud with hyperthreading, one core appears as 2 vCPUs and costs a full license, so each core now costs twice as much.
What you gain is scope. If the four databases fit in 40 vCPUs, you license 20 processors. The shared vCenter in the example attracted 192. Run the numbers both ways before committing. Our guide to Oracle licensing in cloud environments sets out the full rules, including the Named User Plus minimums that apply there.
What will Oracle's audit team say, and how should you answer?
Expect the same few positions in most VMware findings. Answer each one with evidence and a reference to your contract.
- "Your virtual machines can run on any host in the vCenter, so every host needs a license." Ask which clause of your ordering document or master agreement says that. Then show the dated evidence pack for the contained cluster.
- "Affinity rules do not limit licensing." Agree, and point out that your boundary does not rely on them. The separation is in hosts, networks, storage and vCenter.
- "The partitioning policy is clear on VMware." The policy describes itself as educational and excludes itself from any contract. Say you will count against contract terms and treat the policy as Oracle's interpretation.
- "An unlimited agreement would make this go away." Price any ULA against your contained count. Pricing it against the claimed count pays Oracle for hosts you could isolate. Our database ULA negotiation guide shows how.
- "We also found options and packs in use." Packs such as Diagnostics Pack are enabled by default in Enterprise Edition, and each one is counted on the same reachable hosts. Review the usage data before you accept the finding, using our guide to Enterprise Edition options pricing and audits.
Contract wording to ask for at your next purchase or renewal
Oracle will not rewrite its policy for you, but it does sign ordering documents with customer specific terms. Ask for these:
- A named licensed environment. The ordering document identifies the Oracle cluster by name, host count and processor model as the environment the licenses cover. This turns your architecture into a contract term.
- Recognition of movement inside the cluster. Written acceptance that moving virtual machines between hosts of the named cluster, for failover or maintenance evacuation, creates no additional license requirement.
- A defined audit scope. Any audit is limited to the named environment unless Oracle shows evidence that Oracle programs are installed elsewhere. Our audit clause redline covers the drafting.
- Price holds for growth. A fixed unit price for additional processor licenses if you add hosts to the named cluster during the term.
What does containment cost, and how do you build the business case?
Containment costs less than one year of the exposure it removes, in every case we have modeled. Put that comparison in front of the CFO. Isolation projects get funded when they are presented as license avoidance, and stall when they are presented as infrastructure work.
The four cost lines
- Hardware. Dedicated hosts, sized to entitlement, with failover capacity inside the boundary.
- Management separation. A second vCenter and the operational work to run it.
- Migration effort. Moving database virtual machines with tested rollback, usually the largest line.
- Ongoing governance. The change control that keeps the boundary intact after the project team leaves.
How to build the business case
Price three scenarios side by side: the status quo with the reachable pool licensed in full, containment in a dedicated and isolated cluster, and migration to an authorized cloud with the vCPU conversion applied.
Include five years of support at 22 percent with annual escalation in every scenario. Support is where the difference compounds. A comparison that shows only license cost understates the case for containment.
| Time before the renewal | What to do |
|---|---|
| 12 months | Map every host each Oracle virtual machine can reach, and count pinned hosts against the full pool |
| 6 months | Build and migrate to the isolated Oracle cluster, with its own vCenter and storage |
| 3 months | Complete and date the evidence pack, and model the cloud path against staying |
| 1 month | Open the commercial discussion on the contained count, with the contract wording above in your draft |
How does Redress help with Oracle on VMware?
We map the reachable pool, design the contained environment with your platform team, and run the renewal or audit response on the measured position. We do not resell Oracle or VMware, and we do not implement either.
The work runs inside the Vendor Shield subscription, the Renewal Program and the Benchmark Program. If an audit notice has already arrived, start with our Oracle audit defense guide. The Oracle services page, the Oracle knowledge hub, our benchmarking service and the contact page have more.
What to do next
- Map the reach. List every host an Oracle database virtual machine can be migrated to today, and every cluster that shares a vCenter, an SSO domain or storage presentation with it.
- Count both ways. Count the pinned hosts and the full reachable pool, with the core factor applied to each.
- Price the gap. Convert the difference into licenses plus five years of support, so the exposure has a number.
- Design the isolated cluster. Size a dedicated Oracle cluster to entitlement, with failover inside the boundary.
- Split the vCenter. Move the Oracle environment into its own management domain, with separate vMotion networks and credentials.
- Cap the sockets. Put every host addition behind a license check, then build and date the evidence pack before anyone asks for it.
- Model the cloud path. Compare staying with moving, using the vCPU rules instead of core counts.
- Open the renewal on your contained position. Negotiate from the measured count and make Oracle justify any host beyond it.
Want a second opinion on your Oracle position? Our Oracle licensing consultants are former Oracle insiders who now work only for buyers.
Frequently asked questions
Does Oracle count all VMware hosts or only the ones running the database?
All hosts the database virtual machine can reach through live migration. Because VMware is soft partitioning, the hosts it happens to run on set no limit. The count shrinks only when you separate the Oracle hosts physically and in management scope, so migration to other hosts is technically impossible.
Is VMware approved for Oracle hard partitioning?
No. VMware appears in Oracle's soft partitioning list. The approved hard partitioning methods are physical domains, capped Solaris Zones, IBM LPAR and capped micro partitions, capped vPar, nPar, capped Integrity Virtual Machines, capped Secure Resource Partitions and Fujitsu PPAR, plus Oracle's own hypervisors when configured as Oracle's documents describe.
Do DRS host affinity rules limit Oracle licensing?
You should not plan around them. Oracle commonly rejects affinity rules because they can be edited without any hardware change, and audit findings are based on what is technically possible. Physical separation or a separate management domain is what holds up.
Is Oracle's partitioning policy legally binding on us?
The document itself says it is for educational purposes only and may not be incorporated into any contract. That is a real argument if your ordering documents do not reference it. Use it to push a settlement down, and do not treat it as a defense you can rely on alone.
How much can the VMware counting gap cost?
On a large shared vCenter, the difference reaches seven figures once five years of support is included. In our hypothetical 16 host example at the $47,500 list price, counting the whole vCenter instead of 2 pinned hosts adds 168 licenses. That is why isolation projects usually pay back inside a year.
Does a separate vCenter reduce the Oracle count?
Yes, materially, when it is a real separation. Its own vCenter and SSO domain, with no shared vMotion network or administrator credentials, cuts the reachable pool to the Oracle hosts. It is the strongest boundary available short of fully separate hardware.
How does Oracle licensing change on AWS or Azure?
The unit becomes the vCPU. Two vCPUs equal one processor license with hyperthreading enabled and one vCPU without it, and the Processor Core Factor Table does not apply. You lose the reachability argument, but the count can rise on hardware that had a favorable core factor on premises.
Should we tell Oracle about our containment design?
Yes, in writing and at the right time. A dated containment design presented while audit scope is being agreed carries far more weight than the same design produced after a finding. Ideally, record Oracle's acceptance in a contract amendment at your next purchase or renewal.
Does Oracle Standard Edition 2 on VMware follow the same rule?
Yes. SE2 is licensed per occupied socket instead of per core, so the core factor does not come into it, but the reach rule applies in full. Every occupied socket on every host the SE2 virtual machine could migrate to is counted, and each of those hosts must have no more than 2 sockets, the SE2 server limit.