Stitchflow
VMware Tanzu logo

VMware Tanzu SCIM guide

Native SCIM

How to automate VMware Tanzu user provisioning, and what it actually costs

Native SCIM requires Enterprise plan

Summary and recommendation

VMware Tanzu Platform does not offer native SCIM provisioning across its unified platform. While VMware's legacy products like vCenter Server 8.0 U2+ and individual UAA components support SCIM 2.0 endpoints, the consolidated Tanzu Platform relies on JIT (Just-In-Time) provisioning for its console interface. Under Broadcom's ownership, Tanzu is now exclusively bundled with VMware Cloud Foundation at approximately $350 per core annually (minimum 72 cores required), making it a $25,200+ annual commitment before considering provisioning challenges. The platform's complex multi-product architecture means SSO configuration varies significantly across components, creating inconsistent user management experiences.

This fragmented approach creates significant operational overhead for IT teams managing developer and platform engineer access. Without centralized SCIM provisioning, administrators must manually manage user lifecycle across multiple Tanzu components, track access permissions separately, and rely on JIT provisioning that only works when users successfully authenticate. For enterprise environments running cloud-native workloads, this manual process introduces security gaps and compliance risks, particularly when team members change roles or leave the organization.

The strategic alternative

VMware Tanzu gates SCIM behind Enterprise. Skip the Enterprise plan upgrade and automate complete outcomes across your stack. We maintain the integration layer underneath. You focus on judgment, not plumbing.

Quick SCIM facts

SCIM available?Yes
SCIM tier requiredEnterprise
SSO required first?Yes
SSO available?Yes
SSO protocolSAML 2.0
DocumentationNot available

Supported identity providers

IdPSSOSCIMNotes
OktaOIN app with full provisioning
Microsoft Entra IDGallery app with SCIM
Google WorkspaceJIT onlySAML SSO with just-in-time provisioning
OneLoginSupported

The cost of not automating

Without SCIM (or an alternative like Stitchflow), your IT team manages VMware Tanzu accounts manually. Here's what that costs:

Source: Stitchflow aggregate data across apps with 2+ instances, normalized to 500 employees
Orphaned accounts (ex-employees with access)7
Unused licenses12
IT hours spent on manual management/year101 hours
Unused license cost/year$3,925
IT labor cost/year$6,088
Cost of compliance misses/year$1,741
Total annual financial impact$11,754

The VMware Tanzu pricing problem

VMware Tanzu gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.

Tier comparison

PlanPriceSSOSCIM
EnterpriseCustom (bundled with VMware Cloud Foundation)

Pricing structure

PlanPriceSSOSCIM
EnterpriseCustom (bundled with VMware Cloud Foundation)

Market data on VMware costs

VMware Cloud Foundation
~$350/core/year (down from $700 pre-Broadcom)
Minimum commitment
72 core licenses required
Total minimum annual cost
~$25,200/year before support
Price increases of 150-1000%+ reported across VMware products post-acquisition

What this means in practice

No standalone option: Tanzu Platform is now bundled exclusively with VMware Cloud Foundation or vSphere Foundation. You cannot purchase Tanzu separately, forcing organizations to license entire infrastructure stacks even if they only need the platform services.

Forced minimum spend: The 72-core minimum licensing requirement means even small Tanzu deployments carry a $25,200+ annual infrastructure cost before adding platform or support fees.

Complex provisioning landscape: Different Tanzu components handle identity differently:

Tanzu Platform Console
JIT provisioning only
TAS/Cloud Foundry
UAA server with limited SCIM endpoints
vSphere integration
Requires vSphere 8.0 U2+ for SCIM support

Additional constraints

Identity broker migration deadline
Existing VMware identity broker customers must migrate by June 30, 2025
Multi-product complexity
Tanzu spans multiple products (Application Service, Kubernetes Grid, Mission Control) with inconsistent SSO implementations
Limited IdP support
No native support for OneLogin or Google Workspace
Manual user management
Platform engineers must manually create and manage user access across multiple Tanzu services
Subscription-only model
No perpetual licensing options under Broadcom ownership

Summary of challenges

  • VMware Tanzu supports SCIM but only at Enterprise tier (Custom (bundled with VMware Cloud Foundation))
  • Google Workspace users get JIT provisioning only, not full SCIM
  • Our research shows teams manually provisioning this app spend significant hidden costs annually

What VMware Tanzu actually offers for identity

SAML/OIDC SSO (Platform-dependent)

VMware Tanzu's identity management varies significantly across its complex product suite:

ComponentSSO SupportProvisioning Method
Tanzu Platform ConsoleSAML 2.0, OIDCJIT provisioning only
Cloud Foundry (UAA)SAML, LDAP, OIDCSCIM 2.0 via UAA server
vSphere 8.0 U2+SAML 2.0SCIM 2.0 (limited)
Workspace ONESAML 2.0, OIDCSCIM 2.0

Critical limitation: There's no unified SCIM provisioning across the Tanzu platform. Each component requires separate identity configuration and has different capabilities.

The Broadcom Reality Check

Under Broadcom ownership, VMware Tanzu now comes with significant constraints:

Bundling requirement
No standalone Tanzu - must purchase VMware Cloud Foundation (~$350/core/year)
Minimum commitment
72 core licenses required (roughly $25,200/year minimum)
Migration deadline
Identity broker must be migrated by June 30, 2025
Price increases
Reports of 150-1000%+ cost increases post-acquisition

What You Actually Get

The "Enterprise" tier includes:

SAML 2.0 federation for supported components
Just-in-time provisioning for Tanzu Platform Console
SCIM endpoints via UAA (Cloud Foundry only)
Complex multi-product identity management requirements

The problem: You're paying enterprise platform prices for fragmented identity capabilities that require significant integration work across multiple Tanzu components.

What IT admins are saying

Community sentiment on VMware Tanzu under Broadcom ownership is overwhelmingly negative, with IT teams facing dramatic cost increases and forced bundling:

  • Massive price hikes: Reports of 150-1000%+ price increases since Broadcom acquisition
  • Forced bundling: Can no longer purchase Tanzu standalone - must buy entire VMware Cloud Foundation bundle
  • Minimum licensing requirements: 72 core minimum license requirement hits smaller deployments hard
  • Identity migration deadlines: Forced migration from identity brokers by June 30, 2025

VCF pricing went from ~$700/core/year to ~$350/core/year, but now everything is bundled together whether you need it or not. The minimum 72 core requirement means small teams are paying for capacity they'll never use.

Enterprise architect on Reddit

We're looking at a 400% cost increase just to keep our Kubernetes platform running. Broadcom is forcing us to evaluate alternatives.

Platform engineer on VMware community forums

The recurring theme

Broadcom's acquisition has transformed VMware Tanzu from a targeted Kubernetes platform into an expensive, bundled enterprise suite that many organizations can no longer justify, driving mass migration to alternatives like Amazon EKS and Azure AKS.

The decision

Your SituationRecommendation
Small dev team (<10 users) exploring KubernetesManual management acceptable if you can afford the enterprise licensing
Mid-size organization with existing VMware investmentUse Stitchflow: avoid the forced bundling and price increases
Enterprise platform team managing multi-tenant TanzuUse Stitchflow: essential for automated access control across complex environments
Organizations evaluating Kubernetes platformsConsider alternatives like EKS/GKE with Stitchflow for better cost efficiency
Existing Tanzu customers facing license renewalUse Stitchflow with alternative platforms: escape the Broadcom pricing trap

The bottom line

VMware Tanzu under Broadcom ownership has become prohibitively expensive with forced bundling and 150-1000%+ price increases. While the platform offers enterprise-grade Kubernetes capabilities, the lack of native SCIM support and astronomical licensing costs make it a poor choice for most organizations. Stitchflow enables you to get automated provisioning with modern alternatives at a fraction of the cost.

Make VMware Tanzu workflows AI-native

VMware Tanzu gates SCIM behind Enterprise. We build complete offboarding, user access reviews, and license workflows without that SCIM Tax upgrade.

No Enterprise upgrade required
Less than a week, start to finish (~2 hours of your time)
We maintain the integration layer underneath
Book a Demo

Technical specifications

SCIM Version

2.0

Supported Operations

Create, Update, Deactivate, Groups

Supported Attributes

Not specified

Plan requirement

Enterprise

Prerequisites

SSO must be configured first

Key limitations

  • Identity broker migration required by June 30, 2025
  • JIT provisioning for Tanzu Platform Console
  • vSphere SCIM support requires 8.0 U2+
  • Complex multi-product platform with varying SSO support
  • Now bundled only - not available standalone

Documentation not available.

Unlock SCIM for
VMware Tanzu

VMware Tanzu gates SCIM behind Enterprise plan. We automate complete offboarding and access reviews across your stack without that SCIM Tax upgrade.

See how it works
Admin Console
Directory
Applications
VMware Tanzu logo
VMware Tanzu
via Stitchflow

Last updated: 2026-01-11

* Pricing and features sourced from public documentation.

Keep exploring

Related apps

8x8 logo

8x8

SCIM Tax

UCaaS / Business Communications

SCIM StatusIncluded
Manual Cost$11,754/yr

8x8 supports SCIM 2.0 for automated user provisioning, but only on their quote-based X Series plans (previously $24-44/user/month range before they moved to custom pricing). While SCIM can create, update, and deactivate users, it has critical gaps that create ongoing manual overhead: license assignment must be done manually after every user is provisioned, users can't be deleted (only deactivated), and provisioned users don't automatically appear in the Company Directory. For IT teams managing a unified communications platform that typically covers all employees, these limitations defeat much of SCIM's purpose. You're still manually touching every user account to assign licenses and ensure directory visibility. The lack of user deletion support also creates compliance headaches when employees leave - accounts accumulate as "deactivated" rather than being properly removed.

View full guide
Absorb LMS logo

Absorb LMS

SCIM Tax

Learning Management System (LMS)

SCIM StatusIncluded
Manual Cost$11,754/yr

Absorb LMS supports native SCIM provisioning, but only on Enterprise plans with SSO as a required paid add-on. Even with SCIM enabled, the implementation has critical limitations: SAML provisioning only creates accounts on first login and never updates existing users, and full user provisioning requires the specific "Absorb 5 - New Learner Experience" version. For organizations managing compliance training across hundreds or thousands of learners, these gaps create ongoing manual work. The SSO-as-add-on model means you're paying extra fees on top of already custom Enterprise pricing ($6-12/user/month base, but varies significantly). For learning management systems handling external partners, contractors, and employees across different access levels, the inability to update existing user attributes through SAML provisioning forces IT teams into manual account management—exactly what automated provisioning should eliminate.

View full guide
Airbase logo

Airbase

SCIM Tax

Spend Management / Corporate Cards

SCIM StatusIncluded
Manual Cost$11,754/yr

Airbase supports SCIM provisioning, but only on Enterprise plans starting around $8,500/year. While SCIM works with all major identity providers (Okta, Entra ID, Google Workspace), the Enterprise requirement creates a significant barrier for smaller finance teams who need automated provisioning for spend management but can't justify enterprise-level spend management software costs. This creates a particular challenge in finance applications where rapid provisioning and deprovisioning is critical for corporate card access and financial controls. Manual user management means delayed access for new employees needing corporate cards, and more critically, potential security gaps when departing employees retain access to spend management systems. For finance teams handling sensitive financial data and corporate spending, these delays and oversights create both operational friction and compliance risks.

View full guide