Contents
Key takeawaysWhy Oracle claims every hostWhat we see in auditsThe four boundary stepsWhat the boundary costsSetting a boundaryBroadcom changesChecking your exposureProving the boundaryContract terms to ask forWhat to do nextFAQOracle's audit position on VMware is that every physical host a virtual machine could reach needs licenses, up to every host vCenter connects. Your contract and dated configuration evidence decide how much of that claim survives.
- The policy disclaims itself. Oracle's partitioning document says it is educational, is not a contract and may not be incorporated into one.
- The claim widens in four steps. Cluster, then vCenter, then shared storage, then linked vCenters, and each step can be argued and closed with evidence.
- One cluster can mean $18.24 million. A 16 host cluster of two socket, 24 core servers converts to 384 Processor licenses at the 0.5 x86 core factor.
- Only required affinity rules count. A "should run on hosts in group" rule can be broken by DRS, so it does not limit where the database could run.
- Broadcom pricing pushes the wrong shape. Per core minimums reward fewer, larger clusters, which is the geometry that widens an Oracle claim.
- Evidence expires. vCenter task and event retention is commonly 30 days, so migration history must be exported long before an auditor asks.
Why does Oracle claim VMware hosts your database never touched?
Oracle classes VMware as soft partitioning, and its partitioning policy says soft partitioning cannot be used to limit the licenses a server or cluster of servers needs. On that reading the licensable unit is no longer the virtual machine. It becomes every physical host the virtual machine could be moved to.
The weakness in that position is the document it rests on. Oracle's partitioning policy states in its own text that it is for educational purposes only. It adds that it may not be incorporated into any contract and is not a commitment to any specific terms.
What does the partitioning policy say about its own status?
It calls itself guidance. That one paragraph is why every VMware settlement we have defended was argued on contract language and deployment evidence, and never on whether VMware counts as soft partitioning.
- The policy is unilateral. Oracle revises it when it chooses, without your signature. Contract terms cannot change that way.
- Your contract defines the metric. Oracle's own price list defines Processor as all processors where the Oracle programs are installed and/or running. The ordering document and license agreement that carry that definition are what a court would read.
- No published decision settles it. The lawsuit most often cited in this debate ended without a ruling on the partitioning question. Both sides negotiate without precedent.
Why does Oracle still win this argument in most audits?
Most customers cannot answer the follow up question. The auditor asks where the database could have run during the audited period, and the infrastructure team finds that vCenter no longer holds the answer.
A policy that disclaims its own force is weak. It still beats a customer with no evidence at all, and that is the position most audited companies are in when the first technical call starts.
The VMware VCF Renewal: How to Prepare Before Broadcom Names the Price
What have we seen in Oracle on VMware audits in 2024 and 2025?
Between 2024 and 2025, Fredrik Filipsson worked roughly 20 to 30 Oracle audits and pre audit reviews on VMware environments. In none of them was the dispute about whether Oracle was installed. Every one turned on where it could have run.
- Opening claims were inflated by reach. Oracle's first figure priced every host reachable through vCenter, which put it 4 to 10 times above the contained architecture.
- Evidence decided the settlement. Customers who could produce cluster configuration exports and dated change records settled the virtualization line at 10 to 25 percent of the opening claim.
- Advisory rules lost immediately. Every customer with a dedicated Oracle cluster on paper but preferential affinity rules in vCenter lost that point in the first technical call.
Read together, those patterns describe how the negotiation runs. Oracle opens at the widest boundary it can describe and gives ground as the customer puts dated configuration evidence on the table.
Oracle on VMware licensing white paper
Hard versus soft partitioning, the cluster wide claim, and how to contain Oracle licensing on VMware.
Get the white paper →How far does Oracle argue the VMware cluster boundary reaches?
Oracle escalates in four steps, and each step is triggered by something specific in your configuration. Knowing which step you are on tells you what to fix now and what to produce later.
| Step | Oracle's claim | What triggers it | Evidence that stops it |
|---|---|---|---|
| 1 | Every host in the cluster | Any Oracle program installed on any host in that cluster | Cluster membership export and host inventory with core counts |
| 2 | Every host in the vCenter | Migration configured or possible between clusters | Enforced host affinity, separated compute, dated change records |
| 3 | Every host that sees the storage | Oracle datastores presented to hosts outside the cluster | Storage presentation, masking and zoning records for the period |
| 4 | Every host in linked vCenters | Linked mode or migration across vCenter instances | vCenter topology diagram and the permission model that blocks it |
Why are steps 3 and 4 the weakest part of an Oracle claim?
The contractual test asks where the programs are installed and/or running. Steps 3 and 4 drop that test and put reachability in its place. A host that merely sees a datastore, or sits in another vCenter, has neither installed nor run anything, so push back on these steps first.
Step 2 needs more care. If an administrator could vMotion an Oracle virtual machine into another cluster with a few clicks, Oracle will say it could have run there. Your answer has to be configuration that made that migration impossible.
Does the 10 day failover rule cover VMware migrations?
No. Oracle allows an unlicensed failover node in a clustered configuration with shared storage for up to a total of 10 separate days in a calendar year. The allowance is narrow and resets each calendar year, and it does not cover a virtual machine that DRS migrates between hosts for load balancing.
- It covers failover only. A DRS initiated migration is not a failover event.
- It counts days. Oracle counts separate 24 hour periods, so a two hour failover on Tuesday and a three hour one on Friday use two of the 10. Maintenance downtime counts too.
- The nodes must share storage in one place. Oracle's data recovery document requires the nodes to be arranged in a cluster sharing one logical disk array in a single data center.
- The primary node still needs licenses. The allowance covers only the standby node.
- Read the text for your release. Check the Database Licensing Information manual for your version, together with Oracle's data recovery licensing document, which carries the same educational disclaimer as the partitioning policy.
What does a badly drawn VMware boundary cost at Oracle list prices?
In the 16 host example below, the wide boundary costs eight times the contained one at list. The boundary is usually the largest number in an Oracle audit. The example below uses only published list prices, so you can rerun it with your own host counts.
How does the worked example add up?
- The environment. One 16 host cluster. Two sockets per host, 24 cores per socket, so 48 cores per host and 768 cores in the cluster.
- The reality. Six virtual machines run Oracle Database Enterprise Edition. In practice they have lived on two hosts for three years.
- The contested count. 768 cores multiplied by the 0.5 x86 core factor gives 384 Processor licenses.
- The contained count. Two dedicated hosts have 96 cores, and 96 multiplied by 0.5 gives 48 Processor licenses.
- The gap. 336 Processor licenses, eight times what the workload consumes.
Oracle's technology price list sets Enterprise Edition at $47,500 per Processor, and the table below prices both counts at that rate. Neither total is what you would pay after negotiation, but the ratio between them survives any discount.
| Line | Contested boundary | Contained boundary |
|---|---|---|
| Physical cores in scope | 768 | 96 |
| Processor licenses after 0.5 core factor | 384 | 48 |
| Enterprise Edition at $47,500 | $18.24 million | $2.28 million |
| Annual support at 22 percent of license fee | $4.01 million | $0.50 million |
| Partitioning ($11,500), Diagnostics Pack ($7,500) and Tuning Pack ($5,000) added | $27.46 million | $3.43 million |
Why does the options line matter more than the database line?
The options and packs follow the boundary. Every Processor license Oracle claims for the database it also claims for Partitioning, Diagnostics Pack, Tuning Pack and any other option in use. Those three alone list at $24,000 per Processor, roughly half again on top of the database.
That lifts the contested total above $27 million and the contained total above $3.4 million. A management pack switched on by a well meaning database administrator becomes a seven figure item at cluster scale instead of a five figure one. Our note on the feature usage view shows how to see what Oracle will see.
What does each extra host add?
Every two socket, 24 core host that enters Oracle's scope adds 24 Processor licenses. At list that is $1,140,000 of Enterprise Edition and $250,800 a year in support, or $1,716,000 once the three options above are included.
Use that figure in internal debates. When an infrastructure team proposes one more host for a cluster that runs Oracle, the licensing exposure at list dwarfs the hardware cost. The person who owns the Oracle contract should approve that change.
Which number actually gets negotiated?
Settlements land between the two columns, weighted by what each side can prove. They are usually converted into forward cloud or license spend that Oracle can book instead of a back dated compliance invoice. The closer your own evidence gets you to the right hand column, the smaller that forward commitment becomes.
How do you set up a VMware boundary that Oracle cannot widen?
Build the boundary into the vSphere and storage configuration, where an auditor can read it back from exports. Four controls do the work, and each closes a specific step in the table above.
- A separate cluster with enforced affinity. Put Oracle in its own cluster, then set the virtual machine to host rules to the required type, "must run on hosts in group".
- Storage that only the Oracle hosts can see. Present the Oracle datastores to the Oracle hosts only, and keep the masking and zoning records.
- Migration closed at the vCenter level. No linked mode path, and no cross vCenter migration permission for the accounts that touch these workloads.
- A dated evidence file. Configuration exports on a schedule, retained for the full audit reach of your agreement.
Our design note on the dedicated VMware cluster for Oracle covers host sizing and naming, and the Storage vMotion scope page covers the storage side in more detail.
Which affinity rule type counts as a boundary?
Only the required type. VMware documents that DRS, vSphere HA and vSphere DPM never take an action that violates a required rule. A "should run on hosts in group" rule, by contrast, may be broken so those services can keep working. A preferential rule does not constrain where the database could run.
Auditors who know vSphere ask for the rule type by name. If your dedicated cluster relies on a preferential rule, expect Oracle to treat it as a naming convention and price the wider cluster.
A required rule has a cost you must plan for. HA will not restart an Oracle virtual machine on a host outside the group, and maintenance mode cannot move it outside the group either. Size the Oracle host group with enough spare capacity to lose one host and still run every Oracle workload.
Why is a dedicated Oracle cluster not enough on its own?
The usual advice is that a dedicated Oracle cluster makes you safe. We disagree. In several of the VMware matters described above, the customer had a cluster named for Oracle and still lost the boundary argument. The affinity rules were preferential, the datastores were visible to other clusters, and vCenter had discarded the migration history months earlier.
Build the dedicated cluster, and then put as much effort into the dated file that proves it behaved as designed in every quarter of the audit period. In the settlements we have seen, that file set the price.
When is isolation cheaper than containment?
Sometimes the better answer is to take Oracle off the shared hypervisor. Bare metal hosts, an Oracle approved hard partitioning technology or an engineered system remove the reachability argument altogether.
- Bare metal. Simple to license and simple to prove, but expensive in unused capacity.
- Approved hard partitioning. Covered in our guide to implementing Oracle approved hard partitioning, and for IBM Power in our IBM LPAR licensing guide.
- Another hypervisor does not help by default. Microsoft's platform is treated the same way, as set out in our Hyper-V guide, and Oracle has never recognized Nutanix AHV as approved hard partitioning.
- Cloud has its own counting rules. See OCI versus AWS for Oracle workloads for the two conversion regimes.
How did the Broadcom VMware changes affect Oracle licensing?
They made the cheapest Oracle cluster design more expensive to build, and they push companies toward the large clusters that suit Oracle's audit case. Most VMware renewal analyses miss this.
Does the 16 core minimum kill the small host design?
No, but it narrows the saving. The classic containment build used low core count processors in the Oracle cluster, because fewer physical cores mean fewer Processor licenses. Under Broadcom's subscription terms each processor is billed at a minimum of 16 cores, so an eight core processor is charged as sixteen.
Broadcom sets out the counting rules in its own core counting guidance, and the minimum order size on the Cloud Foundation line was raised again during 2025. Perpetual editions are gone, replaced by the subscription bundles on the VMware Cloud Foundation page, so work from your own quote.
| Build | Physical cores | Oracle Processor licenses | VMware cores billed |
|---|---|---|---|
| 2 hosts, 2 sockets, 8 core processors | 32 | 16 | 64 |
| 2 hosts, 2 sockets, 16 core processors | 64 | 32 | 64 |
| 2 hosts, 2 sockets, 24 core processors | 96 | 48 | 96 |
In the first row you pay Broadcom for 32 cores you cannot use, and you save 16 Oracle Enterprise Edition Processor licenses compared with the second row, which is $760,000 at list. The small host build still wins by a wide margin.
Why is cluster consolidation the expensive response?
Faced with per core and per order minimums, infrastructure teams merge small clusters into fewer large ones so they hit the thresholds efficiently. That is the cluster shape that gives Oracle the widest claim.
Every merge that pulls Oracle hosts into a general purpose cluster hands Oracle step 1 of the table for free. It usually happens inside a project that no one labeled as a licensing project, so the Oracle contract owner hears about it during the next audit.
How should you use the Broadcom renewal?
- You are rebuilding anyway. A migration to the subscription editions is the cheapest moment to redraw cluster boundaries you would otherwise never touch.
- The design documents are being written now. Put "Oracle hosts remain in a dedicated cluster with required affinity" into the target state document, where the engineers doing the build will read it.
- The exports already exist. Whoever is sizing the Broadcom quote is running RVTools across your environment. Keep a dated copy for the licensing file.
- The commercial timing lines up. Broadcom renewal analysis is covered in our guide to the Broadcom licensing changes, and the Oracle side in Oracle licensing under Broadcom VMware.
How can you check your own Oracle on VMware exposure?
Run the same collection Oracle's auditors will ask for, before they ask. Everything below uses tools your VMware and database teams already have.
- First count. The RVTools vHost tab lists sockets, cores and cluster for every host. Total the cores in each cluster that runs Oracle and multiply by 0.5 to see the number Oracle will open with.
- Rule type. In PowerCLI, Get-DrsVMHostRule lists every virtual machine to host rule with its type, so a MustRunOn rule can be told apart from a ShouldRunOn rule. In the vSphere Client the same rules sit under the cluster's Configure tab, VM/Host Rules.
- Migration history. Get-VIEvent filtered for VmMigratedEvent and DrsVmMigratedEvent shows which hosts each Oracle virtual machine has actually visited, for as far back as vCenter still holds events.
- Retention. The vCenter settings event.maxAge and task.maxAge control how long that history survives. Broadcom documents that upgrades to vCenter 6.0 or later reset both from 180 days to 30 days.
- Oracle feature use. Query DBA_FEATURE_USAGE_STATISTICS in each database to see which options and packs Oracle will price across the boundary.
Why does vCenter retention decide so many audits?
vCenter does not keep task and event history indefinitely. Retention is a database setting, commonly left at 30 days, so by the time an audit asks about a period two years back the record is gone.
Fixing this costs almost nothing. Export tasks and events to a location you control on a monthly schedule and store them with the change tickets, and consider raising the retention setting as well.
What mistakes cost the most?
- Treating a cluster name as a control. A cluster called ORA_PROD with a preferential rule gives Oracle step 1 and usually step 2.
- Letting the storage team present Oracle datastores broadly. A datastore visible to every host in the data center invites the step 3 claim.
- Running Oracle's collection scripts across every vCenter. An unbounded collection produces the widest possible inventory, and Oracle prices what it receives.
- Screenshots in place of exports. A screenshot taken this week proves nothing about 2023.
How do you prove the boundary once Oracle's audit letter arrives?
With dated configuration exports covering the audited period, produced in a controlled order. Assertions about how the environment was run carry no weight without exports behind them.
What goes into the topology file?
- Cluster and host inventory. An RVTools export keeping the vHost, vCluster, vInfo and vCPU tabs, with physical socket and core counts per host.
- Placement rules. A PowerCLI export of virtual machine to host groups and rules, showing rule type, so a required rule can be distinguished from a preferential one.
- Storage presentation. Datastore to host mapping plus the array side masking and zoning records for the same dates.
- Migration history. vCenter task and event exports covering each quarter, plus the per virtual machine logs that record host changes.
- Change control. The tickets that authorized each cluster change, which turn a configuration file into a dated record.
Our Oracle VMware evidence pack page lists the export settings we use for each item.
In what order should you respond?
- Acknowledge the letter, confirm the contractual audit clause, and agree scope and period in writing before any data is collected.
- Provide the inventory you agreed, from your own exports, instead of allowing an unbounded collection across every vCenter.
- Produce the boundary evidence in one package, so the reachability argument is answered before it is priced.
- Build your own contained number independently, so the first credible figure in the room is yours.
- Close with release language that names the audited period and the virtualization question explicitly.
Our Oracle audit response guide covers the wider sequence, and the partitioning policy in detail sits alongside this page.
What will the auditor say, and how should you answer?
| What Oracle says | What to say back |
|---|---|
| "VMware is soft partitioning, so every host in the vCenter must be licensed." | "The partitioning policy says it is not part of any contract. Which clause in our agreement licenses hosts where the programs are neither installed nor running?" |
| "Your virtual machines could have moved anywhere through vMotion." | "Here are the required affinity rules, the rule type export and the migration events for each quarter. They show where the machines ran." |
| "Please run our collection scripts across all vCenter servers." | "We agreed the scope in writing. We will provide exports for the clusters that run Oracle programs, plus the topology showing their separation." |
| "The shared storage means the other hosts could run the database." | "These are the masking and zoning records. The Oracle datastores were presented only to the Oracle hosts for the whole period." |
Keep the replies factual and put each in writing after the call. Oracle's opening figure comes down when the evidence arrives in a form its technical team can check, and far less when it arrives as argument.
What contract terms should you ask Oracle for on VMware?
Ask for terms that turn the boundary from a policy question into a contract fact. You have the best chance when you are buying something Oracle wants to sell, such as new licenses, a ULA or cloud credits.
- Named licensed hosts or clusters. An ordering document that lists the hosts or cluster where the programs are licensed makes the scope a matter of record.
- A statement on the partitioning policy. Wording that the policy is not incorporated, and that later policy changes do not expand the license requirement for existing deployments, removes the moving target.
- Defined audit scope. An agreed audited period, and data collection limited to systems where Oracle programs are installed, stops the unbounded collection at the source.
- Release language. Any settlement should release the named period and the virtualization question explicitly, so the same argument cannot reopen at the next audit.
Oracle resists most of these as standard terms. Ask anyway, record the answer, and bring the request back at the next commercial event, including a ULA negotiation.
Oracle prices what you can prove, so the deliverable is the dated file showing the cluster behaved as designed for every quarter in the audit period.
What to do next
- Map the reach this week. List every cluster where an Oracle program is installed, and every cluster a virtual machine in those clusters could be migrated to today.
- Fix the rule type. Check the type of every affinity rule protecting an Oracle workload, and convert preferential rules to required rules after checking spare capacity in the host group.
- Stop losing history. Check vCenter task and event retention, raise it, and start a monthly export to storage you control.
- Close the storage path. Present Oracle datastores only to Oracle hosts, and capture the masking and zoning evidence on the day you change it.
- Price both boundaries yourself. Use your own core counts with our core factor guide and the technology price list before anyone else runs the numbers.
- Protect the design. Write the containment design into the Broadcom migration target state document, so the licensing boundary survives the infrastructure project.
- Prepare before a letter arrives. Read the Oracle and VMware licensing white paper and rehearse the audit response sequence with your VMware and database teams.
Frequently asked questions
Do you have to license every VMware host for Oracle?
Oracle's audit position is yes for every host a virtual machine could reach, because it treats VMware as soft partitioning. That position comes from a policy document your contract does not incorporate. In our work, customers with dated cluster evidence settled the virtualization line at 10 to 25 percent of Oracle's opening claim.
Is the Oracle partitioning policy legally binding?
The document itself says no. It describes itself as educational and says it may not be incorporated into any contract. Your license agreement and ordering document govern, so argue from their Processor definition and from deployment evidence, and keep the policy text out of any settlement wording.
Does a dedicated Oracle cluster fix the problem?
Only when it is enforced and documented. Required host affinity rules, datastores presented to Oracle hosts only, and exports covering the whole audit period turn a dedicated cluster into evidence. Without them, Oracle treats the cluster name as a label and prices the wider vCenter.
What is the difference between a should run and a must run affinity rule?
A should run rule is a preference that DRS, HA and DPM may override during contention or maintenance. A must run rule is required, and those services will not break it. It is also the only type an auditor who knows vSphere will accept as a limit on where Oracle could run.
How many Oracle licenses does a 16 host VMware cluster need?
If Oracle wins the cluster argument, count every core in all 16 hosts. With two socket hosts and 24 core processors that is 768 cores and 384 Processor licenses, before any options. If the database is contained on two hosts, the same workload needs 48 Processor licenses.
How did the Broadcom changes affect Oracle licensing on VMware?
Indirectly. Oracle's rules did not change. Broadcom's 16 core per processor minimum raises the VMware cost of small Oracle hosts, and the pressure to consolidate into large clusters widens the boundary Oracle can claim. Put an Oracle contract owner on the VMware redesign team.
How long should we keep vCenter migration records?
For the full audit period your Oracle agreement allows, which is far longer than the vCenter default. Export tasks and events monthly to storage outside vCenter, keep the change tickets with them, and test once a year that you can still read the oldest export.
Does moving Oracle off VMware end the argument?
It can. Bare metal, an Oracle approved hard partitioning technology or an authorized cloud environment each give a countable boundary in place of a reachability claim. The choice depends on how much unused capacity you will pay for in exchange for a simpler audit.