Telco Cloud

Unified SSO for Telco Cloud: Why VMware Cloud Foundation 9.x should Be on Your Migration Roadmap

Telecom operators manage infrastructure across multiple generations of technology. Hardware-centric 4G evolved into virtualized network functions on hypervisors. Cloud-native 5G added Kubernetes, containerized workloads, and a broader ecosystem of application vendors across multiple layers of virtualization. Each generation brought greater capability and greater scale. Until now, Virtualized Network Function (VNF) and Cloud-Native Network Function (CNF) workloads have lived in separate management stacks, each with its own identity configuration, access governance model, and overhead. VMware Cloud Foundation (VCF) 9.x changes that. With the Unified SSO, a unified authorization model and out-of-the-box support for the identity providers telcos already use, it brings VNF and CNF workloads under one identity foundation. The result is one place to configure identity, one place to manage access, and consistent security enforcement across the entire telco cloud.

One control plane for identity management across the entire VCF stack

The Identity Broker is the centerpiece of VCF 9.x Unified SSO. It acts as a single control plane that manages the connection between all VCF components and your chosen identity provider or directory service. Admins configure their identity provider once and the Identity Broker handles authentication consistently across VCF Operations, vSphere, VCF Networking (NSX), and VCF Automation.

Admins log in once and gain seamless access to all VCF management components based on their assigned roles. There is no longer a need to juggle separate URLs, tokens, or credentials across components. VCF single sign-on (SSO) is configured after VCF deployment using a built-in workflow in VCF Operations, which keeps identity management consistent with how the rest of the platform is managed.

For telcos migrating from VMware Telco Cloud Platform, all Telco Cloud Automation capabilities will be available through VCF Automation. The platform has converged, and the identity management improvements in VCF 9.x apply uniformly across the workloads telcos care about.

A note on workload runtime: The Identity Broker and Unified SSO model described here apply to standard management-plane access across the VCF stack. vSphere Pods, Container Runtime Executive (CRX), and PodVM memory optimization are separate capabilities covered in the reference identity blog linked below. Telco workloads in this deployment pattern run as standard virtual machines, not as PodVMs.

Out-of-the-box support for the identity providers you already use

VCF 9.x ships with out-of-the-box integration for the identity providers most telco organizations have already standardized on. Every component in the VCF stack supports the same set of providers: Microsoft Entra ID, Microsoft Active Directory Federation Services (AD FS), Okta, Ping, Federate, and any OpenID Connect (OIDC) or Security Assertion Markup Language (SAML) 2.0 compliant providers. For directory-based services, the platform supports Active Directory / LDAP and OpenLDAP .

This uniformity eliminates a category of per-deployment configuration work. Your organization’s existing identity investment applies across the entire private cloud stack without workarounds or partial support.

MFA enforcement applied to the entire stack from a single policy

VCF 9.x enables multifactor authentication (MFA) across all components through your corporate identity provider, rather than requiring separate MFA configuration in each product. When you configure your identity provider, whether Okta, Entra ID, or another OIDC/SAML 2.0 provider, your organization’s MFA policies propagate uniformly across the entire VCF stack. 

For telcos operating under frameworks such as NIST SP 800-53, NIS2, or the UK Telecommunications (Security) Act 2021, this matters directly. Uniform MFA enforcement across the private cloud is a compliance requirement, not just a best practice. VCF 9.x makes it achievable without custom per-component configuration.

Unified authorization: RBAC across the telco cloud from one workflow

Authentication handles who can get in. Authorization determines what they can do once they are in. VCF 9.x addresses both through the same unified identity foundation. Authorization is now applied uniformly at the private cloud level, across both VNF and CNF workloads together, rather than individually at each component of the stack. Admins assign roles from a single workflow in VCF Operations, giving the team a consistent, auditable access governance model that spans the entire private cloud.

This matters especially for telcos running mixed VNF and CNF environments. Previously, authorization rules for virtualized and containerized workloads were managed in separate stacks. Now both workload types sit under the same RBAC model. Onboarding a new team, updating permissions after a role change, or auditing access before a compliance review are all operations that happen in one place, regardless of workload type.

What unified identity means at telco scale

We see this consistently with telco operators: as the private cloud footprint grows, identity management tasks grow proportionally. Each new site adds component instances. Each new CNF vendor brings new access requirements. With unified identity management in VCF 9.x, operations teams break that proportional growth. Configuration happens once. MFA enforcement is inherited. Role assignments follow a single model. The audit trail covers the entire stack.

For telcos executing network transformation, that consolidation reduces access management overhead, shrinks misconfiguration risk, and makes compliance posture easier to demonstrate.

Multitenancy for all type of workloads

For telcos managing workloads on behalf of multiple internal teams or external customers, VCF 9.x delivers hard, quota-enforced multitenancy across compute, networking, and storage, for both VNF and CNF workloads under the same platform. Providers carve out a slice of the infrastructure, define resource quotas, and the platform enforces those boundaries automatically. Tenants cannot consume resources allocated to others, and they have no visibility into other tenants’ infrastructure.

Identity ties directly into this model. When a provider creates a tenant, they can onboard a specific subset of users from a large corporate identity source scoped precisely to that tenant. Authorization rules then apply within those tenant boundaries, giving providers granular control over who accesses what, without manual configuration at every layer of the stack.

We will cover the full multitenancy story in a dedicated follow-on post.

What to start planning now

Migration from VMware Telco Cloud Platform to VCF 9.x is an opportunity to rationalize identity and access management from the ground up. These four steps give you a clean starting point:

  • Map your current identity configuration. This becomes the baseline for your VCF 9.x Identity Broker configuration.
  • Bring your identity provider team in early. The Identity Broker connects directly to your corporate identity source. 
  • Define your RBAC model before you migrate. Unified authorization is an opportunity to rationalize role assignments across teams. Map out permissions per VCF management component in advance rather than carrying over ad-hoc configurations.
  • Plan for vCenter regrouping. VCF 9.x manages vCenter linking through VCF Operations under the unified SSO model. Account for this reconfiguration in your migration project plan.

For telcos on VMware Telco Cloud Platform, this is one of the clearest operational benefits the migration to VCF 9.x delivers. The technology is ready. Start your migration planning now.

Resources


Discover more from VMware Telco Cloud Blog

Subscribe to get the latest posts sent to your email.