Set up single sign-on with Google Federation

Last updated on Aug 3, 2026

Set up authentication in the Google Admin Console to enable single sign-on (SSO) for your organization.

Google Federation simplifies single sign-on by combining directory creation, domain claiming, and SSO configuration into one workflow. This integration lets you manage Adobe user authentication through Google Admin Console, where Google serves as your Identity Provider (IdP). Users in your Google directory can sign in to Adobe apps and services using their Google credentials.

If your organization uses Google SAML, the Admin Console adds a Google OIDC configuration when users first sign in with Continue with Google. You can disable this configuration to prevent Google sign-in.

Before you begin, ensure you have:

  • Administrator access in Google Admin Console
  • Verified domains in Google Admin Console
  • Knowledge of Google's SAML Apps catalog in Google Workspace
  • System Admin role in Adobe Admin Console

Create the federated directory

Sign in to Adobe Admin Console, navigate to Settings > Identity, and select Create Directory.

Enter a name for the directory, select Federated ID, and select Next.

Select Google and select Next.

Follow the on-screen instructions to create an Adobe SAML app in Google Admin Console, then select Next in Adobe Admin Console.

Create Adobe SAML app in Google Admin Console
Create an Adobe SAML app in Google Admin Console.

After creating the SAML app in Google, the two consoles exchange authentication configuration through metadata files. Google provides an IdP certificate and SSO endpoints; Adobe provides service provider URLs for SAML assertions.

Configure account creation and attributes

Review the automatic account creation setting, which is enabled by default and allows users with valid email domains to create federated accounts automatically on first sign-in.

Select a default country from the dropdown menu in the Attribute mappings section.

Choose whether to update user information in Admin Console when users sign in by selecting the corresponding option.

Select Done to complete directory creation.

Note

When automatic account creation is disabled, you must add users manually or through sync tools.

Learn more about how attribute mappings transfer Google user data to Adobe user profiles.

Add verified domains from Google

In the Adobe Admin Console, navigate to Settings > Identity, then select your newly created directory.

Select the Domains tab and select Add domain.

Select Add domains from Google, then sign in to Google.

Sign in to your Google account that contains the verified domains you want to link to the Adobe Admin Console.

Select one or more domains from the list of available domains and select Confirm.

After adding domains, add users and user groups, then assign them to product profiles. You can also add Google Sync from the Sync tab in directory details to automatically provision users directly from your Google directory.

Deleting the Google OIDC configuration is temporary. It recreates automatically when someone signs in with Continue with Google. To permanently block Google sign-in, disable the configuration instead.