In the Adobe Admin Console, navigate to Settings > Directory Details > Sync and select Add Sync.
Set up Google Sync to automate user provisioning from Google Workspace to Adobe Admin Console.
Automate user management between Google Workspace and Adobe Admin Console by adding sync capability to any existing federated directory with any identity provider. Manage user provisioning directly through Google Admin Console while maintaining your current authentication setup.
Google Sync uses the SCIM protocol for user management. You can control which user information syncs with Adobe. Users specified in the Google Admin Console sync to the Adobe Admin Console and can be assigned to product profiles. Add sync to existing directories with SSO configurations or during new directory setup.
Before you begin
- You must be an administrator in Google Admin Console.
- You must have at least one federated directory.
- You must verify and claim all domains.
Pause the User Sync Tool or UMAPI integration before adding Google Sync. After Google Sync is configured and running, remove the previous integration method to avoid conflicts.
Configure Google Sync
Select Sync users from Google Workspace and select Next.
Select Go to Google Admin Console and sign in with an administrator account.
Follow the configuration steps displayed in the Adobe Admin Console to set up automatic user provisioning in the Google Admin Console.
After completing all steps in Google Admin Console, return to Adobe Admin Console and select Save.
Confirm that your sync source appears in Directory Details > Sync and confirm successful configuration.
Google Sync creates federated user accounts based on your Google Admin Console provisioning settings
Sync Google Organizational Units
Google Organizational Units (OUs) sync to the Adobe Admin Console as user groups. Each OU in Google Admin Console, including the root OU, syncs as a separate group with its associated users. Users in nested OUs appear in multiple groups reflecting the organizational hierarchy.
Set up your Google OUs based on licensing requirements before syncing them to the Adobe Admin Console.
Sign in to your Google Admin Console and navigate to Apps > Web and mobile apps.
Select the Adobe SAML app and navigate to Auto-provisioning > Edit Attribute mapping.
In the Attributes window, select Organizational unit path from the dropdown next to the app attribute urn:ietf:params:scim:schemas:extension:Adobe:2.0:User:organizationalUnit.
Select Save to apply the mapping.
Users are synced to their corresponding groups in the Adobe Admin Console after mapping and saving.
Edit sync configuration
System Administrators can update sync settings after initial setup by selecting Go to Settings from the Directory settings Sync tab.
Available settings:
- Allow editing synced data in Admin Console: Temporarily enables manual editing of synced user data in Adobe Admin Console. Changes made during this period don't affect Google Admin Console data and are overwritten by subsequent sync operations.
- Sync status: Controls whether Google Sync accepts changes from Google Admin Console. When sync status is off, changes made in the Google Admin Console don't push to the Adobe Admin Console.
- Edit user sync configuration: Redirects you to configuration instructions to modify sync setup.
By default, synced user data can only be edited in your identity provider, and changes sync to the Adobe Admin Console. Enable manual editing only when necessary.
Remove Google Sync
Removing sync from a directory leaves the directory, domains, user groups, and users intact while removing read-only restrictions.
In the Adobe Admin Console, navigate to Directory settings > Sync and select Go to Settings.
Select Remove Sync to delete the sync configuration permanently.
In the Google Admin Console, turn off auto-provisioning for the Adobe SAML app to prevent quarantine issues.
You cannot move domains to or from a directory managed by Google Sync. After removing Google Sync from a directory, you can move domains to or from that directory.
After removal, you can reestablish sync with the same or a different directory if needed.
De-provision users
Google Sync enables user deprovisioning through three methods in Google Admin Console:
- Delete or suspend users from Google Workspace
- Remove all groups associated with users from the Provisioning Scope
- Turn off the Adobe SAML app for associated organizational units in Google Workspace
These actions disable users in the Adobe Admin Console. Disabled users cannot sign in and appear as Disabled in the Directory Users list. The user account and cloud-stored assets remain in the organization.
Remove users and associated data
To permanently delete a user and associated data, you must enable editing of synced data before removal.
In the Adobe Admin Console, navigate to Directory settings > Sync, then select Go to Settings.
Select Enable editing to allow temporary manual changes.
Navigate to Users > Directory Users and select the user from the list.
Select the option to delete the user account permanently.
Return to Directory settings > Sync > Settings and select Disable editing.
Deleting a user permanently removes the account and all cloud-stored assets. This action cannot be reversed.
Disable editing immediately after user removal to ensure that the Adobe Admin Console accurately reflects Google Admin Console changes.