Manage SDL profiles and user access

Last updated on Aug 3, 2026

Learn how to control device access through product profiles with user policies, IP restrictions, and machine associations.

Shared Device Licensing (SDL) product profiles let you manage which users and machines can access Adobe apps and services on shared devices. You can use product profiles to control user access policies, restrict access based on egress IP addresses, and associate specific machines with a profile.

Create or edit the product profile

In the Admin Console, go to Products.

Select the product for which you want to configure a shared device product profile.

Select the Product Profiles tab.

Select New Profile to create a profile, or select an existing profile name, then select Settings to edit it.

Enter the profile name, display name, and description.

Select Done.

After the profile is created, configure the following settings:

  • User Access Policy
  • Egress IPs
  • Associated Machines

Configure user access policy

In the product profile, navigate to the User Access Policy tab.

Select Open Access to allow anyone with valid credentials including free Adobe IDs to sign in and use apps on the device. Use this option for public labs or continuing education spaces.

Select Organization user only to restrict access to users you've added to the Admin Console with any supported identity type. Use this for general institutional labs where you want to limit access to enrolled students and staff.

Select Enterprise/Federated users only to restrict access exclusively to users with Enterprise ID or Federated ID accounts. Personal Adobe IDs will not grant access. Use this in K-12 environments or anywhere you need to prevent personal account sign-ins.

Select Save to apply the policy.

Note

The user access policy applies at sign-in time. If a user's credentials don't match the policy, they cannot activate the apps even if the device itself meets other profile requirements.

Set egress IP restrictions

Navigate to the Egress IPs tab in the product profile.

Enter the public IP address or CIDR range that your institution uses to connect to the internet. Your network team can provide these values.

Add each additional address or range on a separate line if your institution connects through multiple egress points.

Select Save to apply the restrictions.

Computers connecting from outside the defined IP ranges cannot use shared device licenses.

Associate machines with the profile

Navigate to the Associated Machines section of the product profile.

Select By Microsoft Active Directory organizational units if your devices are domain-joined and you want to associate all machines in specific OUs. Enter each OU path on a separate line.

Select By LAN IP address range if your labs or shared spaces are organized by internal network segments. Enter each range in CIDR notation or as a start-end pair.

Select By installed package if you've deployed SDL packages and want to associate devices based on which package they received. Select up to 10 packages from the list.

Select Save to apply the machine associations.

Machine association options are applied in the following order:

  1. Active Directory organizational unit
  2. LAN IP address range
  3. Installed package

If a device matches multiple profiles, the highest-priority match is applied.

When a user launches an SDL-licensed app, the licensing service validates all three profile layers. The app activates only when the user's credentials satisfy the access policy, the device's egress IP matches the allowed ranges, and the machine meets the association criteria.

Download activated device report

Navigate to Products and select the product containing the profile you want to audit.

Select the product profile name to open its details.

Select the menu in the upper-right corner and choose Create Report.

Wait for the report to generate on Adobe's server, then open the downloaded CSV file.