Skip to content
Edouard Topin's Blog

vcf-identity-zero-trust · 3 articles

VCF identity and zero trust

Identity federation, SSO and workload firewalling patterns for a zero-trust VCF platform.

Complete

VCF identity and zero trust

Every article

  1. 01

    VCF Identity Broker: where VCF 9.1 single sign-on actually stops

    VCF Identity Broker federates login across the VCF consoles, but the documented perimeter is narrower than the pitch. We map what it covers, what stays local, and the break-glass path.

  2. 02

    Federating VCF identity: Okta, Entra ID, and the generic path

    Four identity providers are documented by name, each with its own protocol path. Everything else goes through generic SAML 2.0 — a route that works without being a support statement.

  3. 03

    vDefend Distributed Firewall: zero trust at the workload level

    Least-privilege policy per vNIC, built on dynamic groups and tags rather than IP addresses — and the honest boundary where federated identity stops and the firewall starts.