I thought with VCF 5.x the advice is to move away from WOA for NSX auth (presumably as Broadcom don't want such a core product dependent upon an app that's now owned by a 3rd party)? When I upgraded from 4.5.1 to 5.1 I changed NSX auth to LDAP and pointed at our AD directly (which was all we were doing with WOA anyway). Previously (4.x) the design guidance was point NSX at a standalone WOA for auth which worked OK (although wasn't the most stable) but I never tried pointing it at a WOA cluster. However, I'd re-evaluate using WOA at all at this point.