In a multi-tenant VCF Automation environment, tenant administrators can successfully push packages to the Embedded Automation Orchestrator instance. This occurs even when the specific tenant is strictly integrated with an external, standalone Orchestrator, and the system Orchestrator is not explicitly configured within the tenant's integrations.
VCF A 9.1
The system is functioning as designed. The authorization flow in VCF Automation natively permits any VM Apps organization (tenant) to access the system Orchestrator. This architecture was intentionally designed to replicate legacy access [vRA 8.x] and authorization models. There is currently no mechanism to restrict or isolate this authorization flow from tenant administrators.
No technical remediation or break-fix action is available as the system is operating according to its architectural design.
The Engineering team has submitted an Enhancement Request to Product Management to formally evaluate modifying the authorization flow in a future release. This evaluation will consider supporting strict tenant isolation for the Embedded Orchestrator.