Servers and Cloud

VMware vCenter Server Setup and Management

If you run more than one ESXi host, vCenter lets you manage them as a single platform. We plan the deployment, the cluster, the update process and vCenter’s own backup together.

CybUP TeamLast updated: 5 min read

In short

VMware vCenter setup covers deploying the vCenter Server Appliance (VCSA), grouping ESXi hosts into clusters, configuring HA, DRS and vMotion, managing host updates with vSphere Lifecycle Manager and organising permissions. It is for companies running more than one ESXi host. CybUp handles the deployment, cluster design, updates, backup and access control.

What does vCenter do, and when do you need it?

vCenter is the management server that lets you run several ESXi hosts from one interface and use cross-host features such as HA, DRS and vMotion. With a single host you usually do not need it. With two or more hosts, and if you want virtual machines to restart automatically on another host when one fails, you do.

To be managed by vCenter, hosts need a paid licence. According to Broadcom’s knowledge base, free ESXi cannot be managed by vCenter and does not include vMotion, DRS or HA. We cover the host side on the VMware ESXi installation page.

“vSphere Hypervisor cannot connect to vCenter and therefore cannot be centrally managed.”

— Broadcom — ESXi 8.0 Update 3e release notes

How do you deploy the vCenter Server Appliance (VCSA)?

vCenter ships as a prebuilt virtual appliance, the vCenter Server Appliance (VCSA), and deployment happens in two stages: placing the appliance on one of the ESXi hosts, then configuring it. Before you start, vCenter needs a static IP address, forward and reverse DNS records and an NTP source. A vCenter deployed with missing DNS records leads to certificate problems that are painful to fix later.

We choose the appliance size (tiny, small, medium and so on) based on the number of hosts and virtual machines and on expected growth. Running vCenter inside the cluster it manages is a common approach. In that case we give the vCenter VM a high HA restart priority and document which host it runs on, so it is easy to find and power on even when vCenter itself is down.

How do you configure a vSphere cluster with HA, DRS and vMotion?

In a cluster, HA restarts the virtual machines from a failed host on the remaining hosts, DRS balances the load across hosts, and vMotion moves a running VM from one host to another without shutting it down. All three need shared storage and a dedicated vMotion network.

The HA setting most often overlooked is spare capacity: in a three-host cluster, the remaining two hosts must be able to carry the full load if one fails. We reserve that capacity with admission control and enable EVC mode where hosts have different CPU generations; otherwise vMotion refuses to move VMs onto the older-generation host. We usually run DRS fully automated, with rules for VMs that must run together or apart (two DCs, for example).

  • HA: capacity reserved through admission control, restart priorities
  • DRS: automation level and VM-VM / VM-host rules
  • vMotion: separate VMkernel network, EVC mode
  • Shared storage: iSCSI, NFS or vSAN

How do you update ESXi hosts with vLCM?

We manage host updates per cluster with vSphere Lifecycle Manager (vLCM), using the “image” method. According to Broadcom’s knowledge base article, the older “baseline” method (formerly Update Manager) was deprecated with vSphere 8 and is set to be removed in the next major release, so we build new clusters on images from the outset.

With images, every host in the cluster is defined by the same ESXi version, the same vendor add-on and the same firmware and driver set. vLCM flags any host that has drifted and updates hosts one at a time, putting each into maintenance mode. If DRS and vMotion are working properly, VMs move between hosts without interruption while this happens. We trial updates on a test cluster or a single host first, then apply them to the whole cluster in a maintenance window.

How do you back up vCenter?

vCenter’s own backup has to be planned separately from your VM backups. According to the Broadcom documentation, a file-based vCenter backup streams the configuration, inventory and, optionally, historical data to a remote system over FTP, FTPS, HTTP, HTTPS, SCP, NFS or SMB, and can be scheduled from the vCenter management interface.

To restore, you deploy a new vCenter appliance and populate it from the backup. We schedule file-based backups to a target other than the storage vCenter runs on, and monitor that the backups are actually being created. In a cluster without vCenter, VMs keep running, but management functions other than HA stop, as does the backup software’s connection to vCenter. That is why vCenter backup belongs in your disaster recovery plan.

“The backed-up data is streamed over FTP, FTPS, HTTP, HTTPS, SCP, NFS, or SMB to a remote system. The backup is not stored on the vCenter Server.”

— Broadcom TechDocs — File-based backup and restore of vCenter Server

How should vCenter permissions be set up?

If everyone logs in to vCenter with the same admin account, you cannot tell who changed what. We connect vCenter to Active Directory as an identity source and grant permissions to AD groups rather than to individuals. The local SSO administrator account ([email protected]) is kept in a vault as a break-glass account.

We split roles by job: infrastructure administrator, application owner who can only power specific VMs on and off, read-only auditor, and a least-privilege service account for the backup software. In a 25-VM environment, for example, giving the development team console and power permissions only on the folder that holds their own test servers stops anyone touching production by mistake. For the AD side, see the Active Directory and Entra ID page.

What you receive

  • vCenter Server Appliance sized and configured with DNS, NTP and certificates
  • Cluster with HA, DRS, vMotion and EVC configured
  • vLCM image definition and host update procedure
  • Scheduled file-based vCenter backup
  • AD integration with role- and group-based permissions
  • Documentation of the cluster, network and permission structure

How we work

  1. 1

    Discovery

    We review your hosts, licences, network and storage design and how the environment is managed today.

  2. 2

    Preparation

    We prepare the IP address, DNS records, NTP and the vMotion network.

  3. 3

    Deployment

    We deploy vCenter, add the hosts to a cluster and configure HA, DRS and vMotion.

  4. 4

    Management

    We set up the vLCM image, the vCenter backup and AD-based permissions.

  5. 5

    Testing and handover

    We test host failure and vMotion, then hand over the documentation.

Frequently asked questions

Does vCenter need its own server?

No. vCenter runs as a virtual appliance on one of the hosts in the cluster. We size it to your host and VM counts.

If vCenter goes down, do the virtual machines stop?

No. Virtual machines keep running and HA carries on working at host level. DRS, vMotion management and the backup software’s connection to vCenter stop until vCenter is back.

Can we add free ESXi hosts to vCenter?

No. According to Broadcom, free ESXi cannot be managed by vCenter. Hosts need a paid licence to be managed through vCenter.

Can you upgrade our existing vCenter?

Yes. We first check version compatibility, plug-ins and backup software support, take a vCenter backup and then plan the upgrade.

How much does a vCenter setup cost?

We give you a written quote after reviewing the number of hosts and your current setup; the review is free.

Will there be downtime during the setup?

Deploying vCenter does not affect running virtual machines. If needed, we schedule short maintenance windows for adding hosts to the cluster and for network changes.

Do you work remotely?

We deploy and configure vCenter remotely anywhere in Türkiye, and work on site in Istanbul for physical tasks.

Sources and official documentation

CybUP Team

Written and reviewed by the CybUP technical team in Istanbul. Last updated: 10 October 2026.

Request a free review for this service

Fill in the form and we will get back to you as soon as possible. For urgent matters, WhatsApp or phone is faster.

Message on WhatsApp

Cookie preferences

Strictly necessary

Required for the core functions of the site and to remember your choices. Cannot be turned off.

Analytics

Lets us measure which pages are visited, anonymously (Google Analytics via Google Tag Manager).

Marketing

Used for advertising measurement and personalisation.