In Admin Console, select Settings > Identity > Directories.
Migrate to a new authentication provider while preserving users, apps, and assets.
Change the identity provider for an existing federated directory in Admin Console. This migration creates a new authentication profile alongside your current one, so you can test it before switching. This applies to federated directories. To configure federation for the first time or to enable directory sync, use the standard directory setup process.
Before you begin
You need:
- System administrator role in Adobe Admin Console
- Existing directory configured for federation
- Access to your organization's identity provider portal with admin credentials (Global Admin for Microsoft Azure, Super Admin for Google, or equivalent for other providers)
- Users assigned to the new SAML application in your identity provider
Add the new authentication provider
Select the directory to migrate, then select Edit.
In the directory details panel, select Add new IdP (identity provider).
Choose the identity provider your organization uses to authenticate users, then select Next.
Configure Microsoft Azure Active Directory
If you selected Microsoft Azure Active Directory:
Sign in with your Microsoft Azure Active Directory Global Admin credentials.
Select Accept at the permission prompt to allow Adobe to create an application in your Azure Portal.
Microsoft Azure AD uses OpenID Connect (OIDC) for authentication. Confirm the Username field in Admin Console matches the UPN field in Azure Portal. If your existing directory uses a different field for User Login Setting, configure the new IdP under Other SAML Providers instead.
Admin Console displays the directory details with the new profile.
Configure Google as an identity provider
If you selected Google:
Copy the ACS URL and Entity ID displayed in the Edit SAML Configuration screen.
In a separate browser window, sign in to Google Admin Console with Super Admin credentials.
Navigate to Apps > SAML Apps.
Select the plus icon to add a new app, then select the Adobe application from the list.
Under Option 2, download the IdP metadata file.
Return to the Adobe Admin Console, upload the metadata file on the Edit SAML Configuration screen, then select Save.
In Google Admin Console, confirm the Basic Information for Adobe, then enter the ACS URL and Entity ID you copied earlier in the Service Provider Details.
Select Apps > SAML apps > Settings for Adobe > Service Status.
Turn Service Status to ON for everyone, then select Save.
Don't set up User Provisioning in Google. Directory sync isn't supported.
Configure other SAML providers
Create a new SAML application instead of editing your existing one to prevent authentication downtime.
If you selected Other SAML Providers:
Open your identity provider admin portal in a new browser window and sign in.
Create a new SAML application in your identity provider without editing any existing SAML configuration.
Copy the Metadata file, the ACS URL, or the Entity ID.
Configure the new SAML application using the values from Adobe Admin Console
In your identity provider, download or copy the metadata file for the new SAML application.
Return to the Adobe Admin Console, upload the metadata file, then select Save.
Test and activate the new authentication profile
In the directory details panel, locate the newly created profile.
Select Test to verify that the configuration functions correctly.
Confirm that the username format in the SAML assertion for the new profile matches the format of the existing usernames in the Admin Console.
Test with two to three active user accounts from the directory to ensure they can authenticate successfully.
Share the test link from your clipboard with other administrators to validate it on different machines, if needed.
After successful testing, select Activate to migrate to the new profile.
Once activated, the new profile displays as In use in the directory details. Your directory now supports up to two profiles of different types simultaneously. For example, Microsoft Azure AD with Open ID Connect can coexist with Other SAML Providers. However, Google, which uses SAML, can’t coexist with Other SAML Providers in the same directory.
After migration, you can move domains from other directories. Users of migrated domains must exist in the identity provider configured for the target directory.