Manage Adobe ID users in enforced directories

Last updated on Aug 3, 2026

Manage existing Adobe ID users in enforced directories and transition them to secure authentication.

Use domain enforcement to block new Adobe IDs from being created on your domains. Existing Adobe ID users tied to your organization's email domains require a managed transition. This transition maintains security without disrupting workflows and data access.

Transitioning to organization-managed identities

Convert existing Adobe ID users to Enterprise ID or Federated ID. Directory users then authenticate through the Admin Console or SSO.

Convert identity types before enabling email change policies to create a uniform sign-in experience. Users maintain access to their work and assets during the transition, and administrators gain centralized authentication and access control.

You can convert users through CSV files in the Admin Console. Access the identity type editing tools through Users and the three-dot menu, which provides an Edit identity type by CSV option for managing multiple users simultaneously.

Requiring email changes for Adobe ID accounts

To preserve Adobe ID accounts for certain users, enable the email change requirement. This policy forces Adobe ID users to change their account email address from an organization domain to a personal email address.

When you activate the policy, users receive an Update Your Email notification. They have 30 days from their first sign-in attempt after policy activation to change their email address. After 30 days, they must change their email address to access their account and data.

The policy only affects the account's email address. User data, assets, and application access remain intact.

Note

Inform users before enabling this policy. Advance communication prevents confusion and helps users understand why they're being asked to change their email address.

Identifying affected users

The personal Adobe ID users report identifies users in your organization who have Adobe ID accounts registered under claimed domains.

Generate this report once per hour for any directory through Insights > Reports in the Admin Console. Use it to assess the scope of affected users before implementing identity transitions or email change policies.

The report helps you plan your transition strategy by showing exactly which users need attention. Regular report generation during migration periods lets you track progress as users convert to Enterprise ID, Federated ID, or change their email address.

Managing the exception list

The exception list exempts specific users from domain enforcement policies, including email change requirements. Users on the exception list can maintain Adobe ID accounts using organization email domains even when enforcement is active.

System administrators use the exception list to maintain Adobe IDs for service accounts, troubleshoot SSO configuration issues, or grant temporary exemptions during transition periods.

Users on the exception list remain exempt only while they appear on the list. Removing a user from the exception list immediately subjects them to active policies, including email change requirements if enabled. This behavior allows administrators to grant temporary exemptions and later enforce standard policies without changing global directory settings.

Understanding policy interactions and timing

Domain enforcement policies interact with identity management in important ways. Convert users to Enterprise ID or Federated ID first. This prevents them from receiving email change prompts when you enable the policy.

If you enable and later turn off the policy, users who haven't changed their email address stop seeing the Update Your Email message. Users who have already changed their email addresses cannot revert their accounts or create new Adobe IDs with their former email addresses unless enforcement is removed from the directory.

Because email address changes are permanent, plan carefully. Consider your long-term identity strategy and user communication approach before activating policies that affect existing accounts.