Manage exception lists for domain enforcement

Last updated on Aug 3, 2026

Add or remove email addresses to exempt users from domain enforcement.

Use exception lists to let users keep Adobe IDs with your organization’s email domain, even under domain enforcement.

Before you begin

Before using the domain enforcement exception list feature, you need:

  • System admin access to the Adobe Admin Console.
  • Domain enforcement enabled in the Admin Console.

Add users to the exception list

Sign in to the Adobe Admin Console and navigate to Settings.

Select the directory that has domain enforcement enabled.

Navigate to Identity settings > Domain enforcement.

Navigate to the Domain enforcement section
Navigate to the Domain enforcement section

Under Exclude specific users from the domain enforcement, select View exception list.

Enter the email address of the user in the text field.

Select Add to add the email address to the exception list.

Select Close when you finish adding addresses.

Note

Adding an email address to the exception list does not create a user account in the Admin Console. You must separately add the user to create the Adobe ID account.

Add exception list users to the trusted or child Admin Consoles

System admins can add Adobe ID users with an enforced domain to a trusted Admin Console or to a child Admin Console within a Global Admin Console hierarchy.

Add the user's email address to the exception list of the enforced parent directory using the procedure above.

Create an Adobe ID account for the user's email address in the Admin Console, using the enforced directory.

Have the admin of the child or trustee Admin Console add that same user as an Adobe ID account to their Admin Console.

Add this user to your Admin Console to create the Adobe ID account in both the parent directory with domain enforcement and the trusted or child Admin Console.

Remove users from the exception list

Navigate to Settings and select your directory that has domain enforcement enabled.

Navigate to Identity settings > Domain enforcement.

Under Exclude specific users from the domain enforcement, select View exception list.

Select Remove selected users.

Select the checkbox next to each email address you want to remove.

Caution

Removing an email address from the exception list does not remove the user account from your Admin Console. You must remove the user from the Users list separately. If the email change policy is enabled, users removed from the exception list must comply with it.