-
Setup and onboarding
- Explore Adobe Admin Console
- Sign-in and access
-
Plan your deployment
- Basic concepts
- Deployment Guides
-
Deploy Creative Cloud for education
- Education Deployment Home
- Education Deployment K-12 Onboarding Wizard
- Education Deployment Simple Setup
- Education Deployment Setup With User Sync
- Education Deployment Setup with Roster Sync
- Education Deployment Key licensing Concepts
- Education Deployment Setup Concepts
- Education Deployment Quick Tips
- Approve Adobe apps in Google Admin Console
- Enable Adobe Express in Google Classroom
- Integrate Adobe Creative Cloud and Adobe Express with Canvas LMS
- Adobe Creative Cloud & Blackboard Learn
- Configuring SSO for District Portals and Learning Management Systems
- Roster syncing for license assignment with the Adobe Admin Console
- Kivuto FAQ
- Primary and Secondary Institution Eligibility Guidelines
-
Licensing
- Licensing overview
- Licensing types
-
Set up your organization
- Identity overview
- Set up identity and Single Sign-On
- Set up organization with Enterprise ID
- Setup Azure AD federation and sync
- Set up Google Federation and sync
- Configure Microsoft AD FS for use with Adobe SSO
- Configuring SSO for District Portals and Learning Management Systems
- Set up organization with other Identity providers
- SSO common questions and troubleshooting
- Set up Frame.io for enterprise
-
Identity and SSO
- Set up identity
- Integrate with Microsoft Entra
- Integrate with Google Sync
- Integrate with other SSO providers
- Troubleshoot
-
Manage your organization setup
- Manage existing directories and domains
- Enable automatic account creation
- Domain Enforcement for restricted authentication
- Set up organization via directory trust
- Migrate to a new authentication provider
- Asset settings
- Manage authentication settings
- Limit product access by IP addresses
- Privacy and security contacts
- Console settings
- Manage encryption
-
Directories, domains, and access
-
Directories and domains
- Create a directory for SAML identity providers
- Verify domain ownership
- Set up domains for directory authentication
- Move domains across directories
- Encrypted and trusted directory domain transfers
- Move directories between Admin Consoles
- Delete directories and domains
- Automatic account creation overview
- Enable automatic account creation
- Automatic federated account creation FAQ
- Domain enforcement
- Directory trusting
-
Directories and domains
-
Manage users
- Adobe Admin Console users
- Administrative roles
- Assign user roles for granular access control
- How to create custom roles
- Manage Frame.io account roles in Adobe Admin Console
- User management strategies
- Assign a license to teams user
- Team Management: Creative Cloud desktop app, Acrobat, Express
- Adobe's matching service
- Edit user identity type
- Manage user groups
- Manage directory users
- Exclude specific users from domain enforcement
- Manage developers
- Migrate existing users to the Adobe Admin Console
- Migrate Frame.io user management to the Adobe Admin Console
- Admin roles and hierarchy
- Enterprise admin permissions matrix
-
Settings
- Asset settings
- Manage encryption
-
Manage products and entitlements
-
Manage products and product profiles
- Manage products on Admin Console
- Add products and licenses
- Manage product profiles for enterprise users
- Manage automatic assignment rules
- Adobe Express Photos FAQs for administrators
- Assign users to Firefly custom models
- Enable Shared Credits for your organization
- Manage product requests
- Manage self-service policies
- Manage app integrations
- Manage product permissions in the Admin Console
- Single App | Creative Cloud for enterprise
- Manage Shared Device licenses
-
Manage products and product profiles
-
User management
- Understand user management
- Manage users and groups
- Manage admins
- Manage user roles
- Migrate users
-
Get started with Global Admin Console
- Adopt global administration
- Select an organization in the Global Admin Console
- Manage organization hierarchy
- Manage product profiles
- Manage administrators
- Manage user groups
- Create license assignment reports for multiple organizations
- Update organization policies
- Manage policy templates
- Allocate products to child organizations
- Execute pending jobs
- Download audit logs and export reports
- Export or import organization structure and product allocations
-
Products and entitlements
- Manage products
- Manage product profiles
- Special programs plans
- Manage entitlements
- Manage automatic assignment
- Manage product access
- Manage self-service policies
- Manage app integrations
- Frame.io integration
- Manage product permissions
-
Manage storage and assets
- Storage
- Manage projects
- Asset migration
- Reclaim assets from a user
- Student asset migration | EDU only
- Manage storage and assets
-
Manage services
- Manage services in the Admin Console
- Configure services
- Optional services
- Adobe Stock
- Enable Shared Credits for your organization
- Custom fonts
-
Adobe Asset Link
- Adobe Asset Link
- Adobe Asset Link Overview
- Create user group for Adobe Asset Link
- Configure Experience Manager Assets as a Cloud Service
- Deploy Adobe Asset Link
- Configure Adobe Experience Manager 6.x Assets for Adobe Asset Link
- Manage assets using Adobe Asset Link
- Adobe Asset Link for Adobe XD
- Troubleshoot Adobe Asset Link
- Known issues with Adobe Asset Link
- Adobe Acrobat Sign
-
Deploy apps and updates
- Overview
-
Create packages
- Packaging apps via the Admin Console
- Create Named User Licensing Packages
- Manage pre-generated packages
- Manage Packages
- Customize packages
- Deploy Packages
- Manage updates
- Adobe Update Server Setup Tool (AUSST)
- Adobe Remote Update Manager (RUM)
-
Deploy apps and updates
- Prepare for deployment
- Manage pre-generated packages
- Create packages
- Customize end-user experience
- Deploy packages
- Use third-party deployment tools
-
Manage Shared Device Licensing (SDL)
- Shared Device Licensing overview
- Deploy Shared Device Licensing
- Manage SDL profiles and user access
- Activate shared device licenses
- Use the Shared Device Licensing toolkit
- Recover shared device licenses
- Shared Device Licensing identity FAQ
- Shared Device Licensing deployment FAQ
- Shared Device Licensing access FAQ
- Known issues in Shared Device Licensing
- Adobe Update Server Setup Tool (AUSST)
- Adobe Remote Update Manager (RUM)
- Troubleshoot
-
Manage your Teams account
- Manage your account
- Complimentary membership for team members
- Update payment details on your Teams account
- Download and email invoices
- Change the contract owner of your Teams account
- Change your Creative Cloud for teams plan
- Change reseller
- Cancel Creative Cloud for teams licenses
- Purchase Authorization Compliance
- Contracts and renewals
- Renewals
- Reports and logs
-
Manage contracts
- Automated expiration stages for ETLA contracts
- Switching contract types within an existing Adobe Admin Console
- Manage trials and special offers
- Complimentary membership for team members
- Creative Cloud for enterprise - free membership
- Frame.io and Creative Cloud for teams and enterprise plans
- Value Incentive Plan (VIP) in China
- VIP Select Help
-
Get started with Global Admin Console
- Get started
- Manage your organization
- Reports audit
-
Get help
- Enterprise and teams | Contact Adobe Customer Care
- Support options
- Teams | Support and Expert Sessions
-
General troubleshooting
- Microsoft Purview Information Protection support in Acrobat
- Use the Creative Cloud Cleaner tool to fix installation issues
- Fix app launch errors on Shared Device Licensing machines
- Technical support boundaries for virtualized or server-based environments
- Resolve trial and license expired errors
- Migrating to OAuth Server-to-Server Credentials
- Manage device authentication for Creative Cloud and Acrobat Pro
- Enterprise | Support and Expert Sessions
Domain enforcement exception lists
Exception lists balance security with flexibility, letting you designate specific users who can bypass domain restrictions.
When your organization blocks personal Adobe IDs on managed email domains, the exception list provides a controlled way to grant access. It applies only to directories with domain enforcement enabled, allowing Adobe ID use for specific business needs even when broader policies prevent the creation of personal accounts.
Exception list use cases
Use exception lists in the following cases when users need Adobe IDs despite domain enforcement:
- Service accounts and automated workflows can’t use federated authentication.
- Technical integrations need Adobe ID credentials that work outside your SSO setup.
- The exception list authorizes these accounts without affecting domain policy.
Exception lists also provide backup access when SSO issues block federated sign-in. If SSO issues block federated sign‑in, an Adobe ID on the list can provide emergency access to the Admin Console or Adobe apps.
When enforcing email changes, you can exclude selected users through the exception list. This flexibility lets you continue using existing Adobe IDs tied to your domain.
Exception list interaction with identity types
Adding an email address to the exception list allows that address to be used for a new or existing Adobe ID account, even though your directory enforces domain restrictions.
You can’t add an email address already linked to an Enterprise ID or Federated ID to the exception list. To move an Enterprise ID or Federated ID user to the exception list as an Adobe ID, remove the email address from the Directory Users list, add it to the exception list, and create the Adobe ID account in your Admin Console.
To convert an exception list Adobe ID to an Enterprise ID or Federated ID, you must first remove the email address from the exception list. Once removed, you can create the Enterprise ID or Federated ID individually or through CSV bulk operations.
Exception list interaction with email change policy
If you enable the required email change policy, any user whose email address appears on the exception list can retain their Adobe ID using your enforced domain. These users are exempt from the mandatory email change requirement that applies to other Adobe ID users.
However, if you later remove an email address from the exception list while the required email change policy is still enabled, that user becomes subject to the policy immediately. Users must change their email address at the next sign-in unless you add them back to the exception list or disable the policy.
Account management considerations
Adding an email address to the exception list allows Adobe ID creation on enforced domains, but it doesn't create the account. You must still add the email in Admin Console to create the account.
Removing an email from the exception list doesn't delete the account. Remove accounts separately in the Users list.
The Admin Console Users list shows an icon next to each Adobe ID, indicating whether it's enforced or allowed by exception. This helps you quickly identify users with exception status.
Exception list access
System administrators can view and modify the exception list through the domain enforcement settings.
Exception lists are available under Settings > Identity in the directory with domain enforcement enabled. To edit the exception list, you select the Exclude specific users from the domain enforcement under Domain enforcement.
To add a user, you enter the email address of a new or existing user in the exception list interface. Once added, that email address is exempt from domain enforcement restrictions.
If you want to create an Adobe ID account for the user, you must add the user through the Users > Add Users workflow in your Admin Console.
Exception lists in trusted and child Admin Consoles
Organizations with directory trust or Global Admin hierarchies can add Adobe ID users from enforced domains to trusted or child Consoles. As a directory admin, add the user’s email to the parent directory’s exception list, then create the account in the parent Admin Console. Once created, child or trustee Consoles can add the same user.
Audit trail and automated account creation
Audit logs record exception list changes, showing who updated them and when, under Insights > Logs.
Adobe workflows may automatically create Adobe ID accounts on enforced domains. This can happen when adding administrators to contracts or granting access to Enterprise commerce apps, such as the Licensing Web Portal.
These automatic account-creation events are also logged, giving administrators visibility into Adobe ID activity even when users are not added via the exception list.