Sign in to the Admin Console and navigate to Settings > Identity.
Learn how Adobe users with federated domains can automatically create accounts via SSO.
Automatic account creation simplifies onboarding by letting users with organization-owned email domains create federated accounts via your SSO system.
New federated directories have automatic account creation turned on by default. Enable it for existing directories and claimed federated domains. Trustees of federated directories can’t change this setting.
You can only enable automatic account creation for the federated domains that your organization owns and has claimed. Trustees of your federated directories cannot enable or disable automatic account creation.
Before you begin
You require at least one federated directory configured in the Admin Console.
Configure automatic account creation
Select an active federated directory, then navigate to Authentication.
Select Edit on the identity provider card.
Navigate to the account creation settings.
Toggle automatic account creation on or off for the identity provider. Turning off this feature prevents new automatic account creation. Existing accounts remain active.
Select a default country in the Attribute mappings section.
Select how to update user information at sign-in: Don't update (default), Always update, or Update when not empty.
Select Done to save your configuration.
Attribute mappings
Adobe reads specific attributes from your federation token to populate account information. For example, Adobe reads first name, last name, email, and country attributes from the federation token to create accounts. Email is required. Other attributes are optional but recommended for distinguishing users in the Admin Console.
|
Identity Provider |
First Name |
Last Name |
|
Country |
|
SAML |
FirstName |
LastName |
|
CountryCode |
|
Azure OIDC |
given_name |
family_name |
|
ctry |
|
OIDC |
given_name |
family_name |
|
address.country |
If no country value is provided or the value isn't an Adobe-supported country, accounts are provisioned without a country by default. You can specify a default country to apply in these cases. Learn more about federated directory setup.
User information updates
Choose how to update user attributes when users sign in:
- Don't update: User information is not updated upon sign-in (default option).
- Always update: User information is always updated upon sign-in.
- Update when not empty: Only non-empty attribute information is updated on sign-in. For example, if a user signs in and your directory shows an updated last name but no first name, only the last name is updated, leaving the first name unchanged.
If an identity provider or its parent directory becomes inactive, automatic account creation is disabled for that IdP. The change does not affect other IdPs within the federated directory.