Hi Mike,
I assume your ESXi management vmkernel is on management VLAN, DNS & AD are also on Management VLAN.
In this case, you would only need the vCenter to be attached to the Management VLAN PortGroup.
In my opinion it is also not a good security practice to share Management VLAN with VM VLAN, vCenter should belong in the Management VLAN.
Do you have a requirement or reason why you would need to connect vCenter to the VM VLAN PortGroup
Bayu Wibowo | VCIX6-DCV/NV
Author of VMware NSX Cookbook http://bit.ly/NSXCookbook
https://github.com/bayupw/PowerNSX-Scripts
https://nz.linkedin.com/in/bayupw | twitter @bayupw