Friday, 4 September 2026

ESX 9.1 in VMware Cloud Foundation: A Major Leap Forward for Automation, Security, AI, and Performance

 

VMware Cloud Foundation (VCF) 9.1 introduces one of the most significant updates to ESX in recent years, delivering major enhancements across installation, storage, security, virtualization, AI infrastructure, memory management, and operational efficiency. Whether you're managing traditional enterprise workloads, modern Kubernetes platforms, or AI and HPC environments, ESX 9.1 provides new capabilities designed to simplify operations while improving performance, resiliency, and security.

Let's take a closer look at the key innovations introduced in ESX 9.1.


Simplified Host Deployment with Zero Touch Provisioning

One of the standout features in VCF 9.1 is Zero Touch Provisioning (ZTP), a modernized approach to ESX deployment.

Traditionally, provisioning ESX hosts at scale required PXE boot infrastructure, TFTP servers, and significant network configuration. ZTP eliminates these dependencies by leveraging secure UEFI boot and HTTPS-based image delivery.

Benefits include:

  • No PXE infrastructure requirements
  • No TFTP configuration
  • Faster and more secure installations
  • Ability to provision multiple hosts from a single HTTPS endpoint
  • Simplified deployment for bare-metal environments

ZTP effectively replaces the legacy Auto Deploy model, which was deprecated in VCF 9.0, making large-scale ESX deployments significantly easier to manage.


Enhanced RDMA Visibility and Troubleshooting

As organizations continue adopting high-performance networking technologies such as vSAN over RDMA and NVMe over RDMA, observability becomes increasingly important.

ESX 9.1 introduces new tools to improve RDMA troubleshooting and validation:

RDMA Sniffer

The new command:

pktcap-uw --capture RDMASniffer
``

allows administrators to perform native packet captures for RDMA traffic directly from the hypervisor.

RDMA Performance Validation

The built-in:

rdmaperf-uw

utility enables administrators to:

  • Validate network readiness
  • Verify end-to-end connectivity
  • Measure throughput
  • Analyze latency
  • Troubleshoot RoCEv2 environments

These additions provide much-needed visibility into high-performance network deployments without relying on external tools.


Guest Customization APIs Become More Flexible

Automation continues to be a major focus area, and ESX 9.1 enhances Guest Customization APIs with several highly requested capabilities.

Improved Powered-Off VM Customization

IPv6-Only Networking

Administrators can now explicitly disable IPv4 and deploy VMs using IPv6-only configurations through both the UI and API.

This simplifies modern networking deployments and removes the need for placeholder IPv4 settings.

Partial Network Customization

Previously, modifying network settings often required submitting a complete customization profile.

Now, administrators can update only the network-related parameters, reducing complexity and making automation workflows more efficient.

Expanded Credential Management

New functionality includes:

  • Setting Linux root passwords during deployment
  • Resetting Linux root passwords on existing VMs
  • Resetting Windows Administrator passwords
  • Enhanced Windows guest script execution

These additions provide greater operational flexibility while improving day-two management.

Live Network Changes for Powered-On VMs

Perhaps one of the most impactful enhancements is live network customization.

Network settings can now be modified on running virtual machines without requiring a shutdown, helping administrators reduce downtime and improve operational agility.


Modernized ESX Host Client

The ESX Host Client receives a refreshed experience aligned more closely with the vSphere Client.

The updated interface improves management of:

  • Compute resources
  • Storage configuration
  • Networking operations

Importantly, VMware has maintained full feature parity while delivering a more modern and consistent management experience.


Faster, Smoother Snapshot Operations

Snapshot operations have long presented challenges for VMs with large virtual disks.

ESX 9.1 introduces a significant enhancement to Change Block Tracking (CBT) enablement.

While overall snapshot creation time remains unchanged, VMware has eliminated the VM unresponsiveness that could previously occur during CBT initialization on large disks.

For production workloads, this translates directly into improved user experience and reduced operational impact during backup and snapshot activities.


Linked Clones for First Class Disks

Storage efficiency and rapid provisioning receive a boost with support for linked clones of First Class Disks (FCDs).

This capability enables:

  • Faster storage consumption
  • Improved efficiency for container platforms
  • Rapid provisioning of persistent volumes
  • Better VMware Kubernetes Service (VKS) integrations

Organizations running cloud-native workloads can particularly benefit from faster and more scalable storage operations.


Expanding AI and HPC Infrastructure Support

AI infrastructure continues to drive hardware innovation, and ESX 9.1 significantly expands support for modern accelerators.

NVIDIA ConnectX-7 and BlueField-3

Enhanced DirectPath now supports:

  • NVIDIA Mellanox ConnectX-7
  • NVIDIA BlueField-3

This enables high-performance passthrough architectures while preserving virtualization benefits such as:

  • vMotion
  • Storage vMotion
  • Live Patch
  • Hot-add and hot-remove operations

AMD MI350 GPU Support

ESX 9.1 also introduces support for the AMD MI350 accelerator platform.

The result is:

  • Faster AI training
  • Improved inference performance
  • Continued virtualization flexibility
  • Better operational management of AI infrastructure

Organizations investing in AI workloads can take advantage of near-native performance without sacrificing manageability.


New Hardware Platform Support

VMware continues to expand hardware compatibility with support for the Intel E825 network controller, integrated into Intel Xeon Generation 6 (Granite Rapids-D) systems.

This ensures organizations can confidently deploy next-generation server platforms while maintaining ESX compatibility.


IOMMU Virtualization for AMD DirectPath Workloads

ESX 9.1 introduces IOMMU virtualization for AMD hosts using DirectPath devices.

This enhancement delivers:

  • Near-native device performance
  • Improved memory isolation
  • Enhanced security
  • Better workload efficiency

For performance-sensitive workloads, this represents an important advancement in passthrough device support.


Significant Security Advancements

Security is one of the strongest themes throughout the ESX 9.1 release.

Quick Boot for Confidential VM Environments

Administrators running confidential workloads can now take advantage of Quick Boot.

Rather than requiring:

  • Full hardware reboot
  • Firmware initialization
  • Lengthy maintenance operations

Quick Boot allows hosts to restart significantly faster, reducing upgrade and maintenance windows.


User-Level Monitor (ULM)

Perhaps the most transformative security enhancement is the introduction of User-Level Monitor (ULM) as the default monitor for all virtual machines.

ULM fundamentally rearchitects how virtual machines are executed by:

  • Moving significant functionality out of privileged kernel space
  • Reducing hypervisor attack surface
  • Limiting opportunities for guest-to-host compromise
  • Improving overall platform security

This represents a major evolution in ESX virtualization architecture.


AMD SEV-SNP Reaches General Availability

After a limited availability period in ESX 9.0, AMD Secure Encrypted Virtualization Secure Nested Paging (SEV-SNP) is now generally available.

Key capabilities include:

  • Hardware-based Trusted Execution Environment (TEE)
  • Memory encryption
  • Memory integrity verification
  • Replay attack protection
  • Memory remapping protection
  • Remote attestation

Supported on AMD EPYC Milan (Zen 3) and newer processors, SEV-SNP delivers stronger protection for highly sensitive workloads.


Intel TDX Now Generally Available

Intel Trusted Domain Extensions (TDX) also achieves general availability in ESX 9.1.

TDX provides:

  • Confidential computing capabilities
  • Hardware-backed attestation
  • Isolation from host-level threats
  • Data confidentiality protection

Support begins with Intel Xeon Gen 5 (Emerald Rapids) processors and newer platforms.

Together, SEV-SNP and TDX establish ESX 9.1 as a leading platform for confidential computing.


Improved Logging Performance

System observability continues to improve through enhancements to vmsyslogd.

The service now handles greater logging volumes across:

  • TCP
  • SSL
  • UDP

For environments generating large quantities of log data, this translates into improved reliability, performance, and operational visibility.


Memory Tiering Becomes Easier and More Resilient

Memory Tiering receives some of the most practical operational improvements in ESX 9.1.

No Reboot Required

Administrators can now:

  • Enable Memory Tiering
  • Configure Memory Tiering
  • Select tiering devices

without requiring a host reboot.

This dramatically reduces deployment time and maintenance costs.

Support for All VM Types

Previous restrictions have been removed, allowing Memory Tiering to support:

  • Low-latency workloads
  • Security-focused workloads
  • Large memory-intensive "monster" VMs

RAID1 Protection for Tiered Memory

Perhaps most importantly, ESX 9.1 introduces software RAID1 mirroring for Memory Tiering devices.

Benefits include:

  • Increased resiliency
  • Protection against NVMe failures
  • Continuous operations during device outages
  • No performance degradation

With mirrored NVMe devices, memory tiering remains available even when a primary device fails.


Final Thoughts

ESX 9.1 represents far more than a routine platform update. VMware has focused on the areas most important to modern infrastructure teams: automated deployment, AI readiness, confidential computing, security hardening, operational efficiency, and infrastructure resiliency.

From Zero Touch Provisioning and live guest customization to User-Level Monitor, confidential computing technologies, RDMA observability, and enhanced memory tiering, ESX 9.1 delivers meaningful improvements for both cloud-scale operators and enterprise data centers.

For organizations planning their next VMware Cloud Foundation upgrade, ESX 9.1 offers compelling reasons to move forward, providing a more secure, flexible, and future-ready platform for today's workloads and tomorrow's innovations.