Skip to content

SAM in the data centre

The desktop is the easy half. Data centre software licensing breaks on three things — publisher metrics, platform variety and virtualisation — and generic discovery tools fail on all three.

Most organisations understand why software in the desktop environment needs managing. Far fewer apply the same attention to the data centre, which is where the money and the risk actually are. Per unit, data centre software is the most expensive thing most IT departments buy, and it is licensed on metrics that were designed to be difficult.

The complexity is not accidental. Desktop licensing counts things you can see. Data centre licensing counts things that are inferred — cores behind a virtualisation layer, users who never log in directly, processing capacity that varies by the hour. Compliance is correspondingly harder to establish and much more expensive to get wrong.

The problems fall into three categories: publisher licensing models, platform variety, and virtualisation.

Publisher licensing models

The four publishers that dominate the data centre — Microsoft, IBM, Oracle and SAP — each license on a different basis, and each basis is complicated in its own direction.

  • Microsoft licenses its server products on physical cores, with minimums per processor and per server, and with cluster and virtualisation rules layered on top. Client and user access licences sit alongside that, and external connector licensing covers people outside the organisation.
  • IBM uses capacity-based metrics, Processor Value Unit and Virtual Processor Core among them, where the licensable quantity depends on the hardware underneath and on whether you qualify for sub-capacity terms at all.
  • Oracle licenses by processor with core factors that vary by chip, and by Named User Plus with minimums per processor. Then there are the options and management packs, which are licensed separately and can be enabled without anyone deliberately buying them.
  • SAP licenses largely by user type, with engines metered on business measures, which means the entitlement question is really a user classification question.

Assessing entitlement against actual deployment across four models like these is not something you can do accurately by hand, and the failure mode is not a small error. It is a category error — counting the wrong thing entirely, then defending the total.

CerteroX SAM ships dedicated licence engines for six publishers: Microsoft, Oracle, IBM, SAP, Adobe and Salesforce. That is the difference between a tool that tells you that you have four hundred installations of Oracle Database and one that tells you which options are enabled, which cores are licensable under which core factor, and which hosts are covered down by an Enterprise Edition pool. The first number is easy to produce and worth very little. The second is where the audit finding lives.

Specifically:

  • Oracle. Options and packs with evidence and override, processor types and core factors, licence pools with hosting rights and geographic rules, cover-down logic for Enterprise Edition, uncapped quantity for unlimited agreements, and E-Business Suite responsibilities.
  • IBM. PVU and Virtual Processor Core metrics, an ILMT connector with compliance gap analysis, and Component Resolution that matches deployed components to products with a scored suggestion you can apply in bulk — plus enforcement of the 30-minute inventory cycle that sub-capacity licensing actually requires. Miss that cycle and IBM is entitled to licence you at full capacity.
  • SAP. A non-invasive ABAP connector reads named users de-duplicated across systems, along with roles, role groups, engines and authorisation definitions, without touching production. Priority-ordered analysis rules then propose the licence type each user should hold, so current, suggested and optimal positions sit side by side.
  • Microsoft. Device CALs, user CALs, named user and external connectors, alongside SQL Server and Windows Server core and processor licensing with cluster and virtualisation awareness.

On Oracle there is one more thing worth knowing. Certero is a verified third-party tool vendor under Oracle License Management Services: Oracle’s audit team can accept data from Certero during an official audit, as an alternative to installing Oracle’s own measurement tools. If you have ever had to run LMS scripts across production under time pressure, you will understand why that matters.

Platform variety

A modern data centre does not run one thing. Alongside the four publishers above sit Unix and Linux in several varieties, and each of them has its own inventory characteristics.

This is where generic discovery tools have historically fallen over. The assumption was that data centre inventory has to be agentless, because agents are not welcome on production Unix, and agentless collection across heterogeneous platforms is genuinely hard. The result was thin, unreliable data on exactly the systems where the licensing stakes are highest.

That assumption no longer holds. CerteroX ITAM has a native inventory agent for Windows, macOS, Linux, IBM AIX, HP-UX and Oracle Solaris — six operating system families, one agent, one schema, the same inventory cycle and the same licence engine. Where an agent is genuinely not permitted, there is a command-line inventory (csinvcli), agentless collection, and standalone inventory for air-gapped and offline systems. Network discovery sweeps a class-C subnet in under five seconds across NetBIOS, SNMP and ICMP, then probes to work out where an agent could be deployed, so you find the machines before you own the problem.

Ten discovery methods in total, all landing in one schema. That is the part that matters for a data centre: there is no reconciliation project between the Unix picture and the Windows picture, because there are not two pictures.

Virtualisation

Virtualisation changes licensing, not just deployment, and it is the most reliable source of unpleasant surprises in the data centre.

Nearly every publisher’s rules differ between physical and virtual environments, and the recurring theme is that small changes to the virtual configuration can have very large licensing consequences. Converting a physical machine to a virtual one changes the licensing basis. Adding a host to a cluster can change what is licensable far beyond the workload you added. Enabling live migration can multiply a requirement, because many metrics count where a workload could run rather than where it does.

Maintenance conditions matter too. Some publishers attach conditions to server applications deployed across virtual servers — Microsoft requires active maintenance for certain server products in that configuration — and losing that condition can invalidate the entitlement you were relying on.

None of this can be assessed without an accurate map of which guest is running on which host, refreshed continuously. CerteroX ITAM connects to VMware, Microsoft Hyper-V, Citrix XenServer, IBM HMC, Oracle VM, Red Hat oVirt and Nutanix, and it is that host-to-guest relationship the licence engines compute against.

The commercial risk is straightforward to state. If you cannot see the relationship between the virtual and the physical, you can end up paying more in additional licences and settlement costs than virtualisation ever saved you — and you will find out under audit conditions with a deadline attached.

What good looks like

The data centre rewards depth over breadth. A tool that recognises ten thousand desktop applications and cannot tell you whether Diagnostics Pack is enabled on an Oracle instance has not helped you with the expensive part.

CerteroX ITAM and CerteroX SAM are one platform with one data model — the same inventory feeding the same licence engines, with software recognition resolving against a Software Recognition Database of more than 3.5 million titles, and the effective licence position computed continuously rather than reconstructed the week the letter arrives.

That covers the data centre publishers that bite: Microsoft, IBM, SAP, Oracle, and the Unix and Linux platforms underneath them.

To see Unix, virtualisation and the licensing rules that sit on top of them handled in one place, book a demo.

Related reading

Other posts covering the same ground.

  • Device-based licensing and access control

    Locking an application down at user level does not make you compliant with a per-device licence. In a Citrix or RDS environment, one user with access can cost you a licence for every device in the organisation.

    • ITAM
    • SAM
    • Governance
    4 min
  • Gartner Myth Buster – Part 1

    A third-party summary of a vendor can be wrong, and it stays wrong for as long as people read it. The case for checking a vendor's facts at source — and the current, sourced record for Certero.

    • ITAM
    • SAM
    • Governance
    7 min
  • The role of good data in software audits

    An audit is won or lost on the quality of your inventory long before the letter arrives. Six ways data goes wrong, and what it takes to have the answer already in hand.

    • ITAM
    • SAM
    • Governance
    8 min
From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.