Create a directory for SAML identity providers

Last updated on Aug 3, 2026

Configure a federated directory with SAML-based identity providers to enable SSO authentication.

Creating a directory in the Adobe Admin Console establishes the foundation for user and license management in your organization. It holds users, domains, and authentication policies similar to LDAP or Active Directory structures.

This procedure applies to SAML providers, including Microsoft AD FS, Okta, Ping, Shibboleth, and similar identity systems.

Before you begin

Ensure you have:

  • System Admin role in Adobe Admin Console
  • Organization's identity provider (IdP) portal access
  • SAML metadata download or configuration capability in your IdP system

Set up the directory and configure IdP integration

Sign in to the Admin Console, navigate to Settings > Identity > Directories, and select Create Directory.

Enter a descriptive name for your directory, select Federated ID, and then select Next.

Select Other SAML Providers and then select Next.

On the Set up IdP screen, choose a method to exchange metadata with your identity provider.

  • Method 1: Select Download Adobe Metadata file to save the XML file to your local system, then upload this file to your IdP's SAML configuration.
  • Method 2: Copy the ACS URL and Entity ID values displayed on screen, then manually enter these into your IdP's SAML configuration fields.
Get setup information for your identity provider
Get set up information for your identity provider.

Open your IdP app, finish the SAML setup using either the uploaded metadata file or the ACS URL and Entity ID, then download your IdP metadata file.

Return to the Adobe Admin Console, upload the IdP metadata file on the Set up IdP screen, and select Next.

Leave automatic account creation enabled unless your organization requires manual user provisioning. When enabled, users with verified email domains can automatically create federated accounts upon first sign-in.

Select a default country from the dropdown menu in the Attribute mappings section, optionally enable the setting to update user information in Admin Console when users sign in, and select Done.

Note

Some identity providers, like Salesforce, require you to extract certificate information from the downloaded Adobe metadata file and enter it separately in the IdP software rather than uploading the complete file.

After creating your directory, verify domain ownership and add domains to the directory to enable user authentication. Learn more about identity setup and identity management in the Admin Console.