Domain enforcement exception lists

Last updated on Aug 3, 2026

Exception lists balance security with flexibility, letting you designate specific users who can bypass domain restrictions.

When your organization blocks personal Adobe IDs on managed email domains, the exception list provides a controlled way to grant access. It applies only to directories with domain enforcement enabled, allowing Adobe ID use for specific business needs even when broader policies prevent the creation of personal accounts.

Exception list use cases

Use exception lists in the following cases when users need Adobe IDs despite domain enforcement:

  • Service accounts and automated workflows can’t use federated authentication.
  • Technical integrations need Adobe ID credentials that work outside your SSO setup.
  • The exception list authorizes these accounts without affecting domain policy.

Exception lists also provide backup access when SSO issues block federated sign-in. If SSO issues block federated sign‑in, an Adobe ID on the list can provide emergency access to the Admin Console or Adobe apps.

When enforcing email changes, you can exclude selected users through the exception list. This flexibility lets you continue using existing Adobe IDs tied to your domain.

Exception list interaction with identity types

Adding an email address to the exception list allows that address to be used for a new or existing Adobe ID account, even though your directory enforces domain restrictions.

You can’t add an email address already linked to an Enterprise ID or Federated ID to the exception list. To move an Enterprise ID or Federated ID user to the exception list as an Adobe ID, remove the email address from the Directory Users list, add it to the exception list, and create the Adobe ID account in your Admin Console.

To convert an exception list Adobe ID to an Enterprise ID or Federated ID, you must first remove the email address from the exception list. Once removed, you can create the Enterprise ID or Federated ID individually or through CSV bulk operations.

Exception list interaction with email change policy

If you enable the required email change policy, any user whose email address appears on the exception list can retain their Adobe ID using your enforced domain. These users are exempt from the mandatory email change requirement that applies to other Adobe ID users.

However, if you later remove an email address from the exception list while the required email change policy is still enabled, that user becomes subject to the policy immediately. Users must change their email address at the next sign-in unless you add them back to the exception list or disable the policy.

Account management considerations

Adding an email address to the exception list allows Adobe ID creation on enforced domains, but it doesn't create the account. You must still add the email in Admin Console to create the account.

Removing an email from the exception list doesn't delete the account. Remove accounts separately in the Users list.

The Admin Console Users list shows an icon next to each Adobe ID, indicating whether it's enforced or allowed by exception. This helps you quickly identify users with exception status.

Exception list access

System administrators can view and modify the exception list through the domain enforcement settings.

Exception lists are available under Settings > Identity in the directory with domain enforcement enabled. To edit the exception list, you select the Exclude specific users from the domain enforcement under Domain enforcement.

To add a user, you enter the email address of a new or existing user in the exception list interface. Once added, that email address is exempt from domain enforcement restrictions.

If you want to create an Adobe ID account for the user, you must add the user through the Users > Add Users workflow in your Admin Console.

Exception lists in trusted and child Admin Consoles

Organizations with directory trust or Global Admin hierarchies can add Adobe ID users from enforced domains to trusted or child Consoles. As a directory admin, add the user’s email to the parent directory’s exception list, then create the account in the parent Admin Console. Once created, child or trustee Consoles can add the same user.

Audit trail and automated account creation

Audit logs record exception list changes, showing who updated them and when, under Insights > Logs.

Adobe workflows may automatically create Adobe ID accounts on enforced domains. This can happen when adding administrators to contracts or granting access to Enterprise commerce apps, such as the Licensing Web Portal.

These automatic account-creation events are also logged, giving administrators visibility into Adobe ID activity even when users are not added via the exception list.