Directory setup scenario
Microsoft Entra ID Sync automates user management for your Adobe Admin Console directory. Add it to any federated directory, regardless of its identity provider.
If your identity provider is Microsoft Entra ID and you do not have a federated directory in the Adobe Admin Console, set up federation in one of these ways:
- OpenID Connect (OIDC): create a federated directory in seconds via OIDC. Most of the setup is in the Adobe Admin Console.
- SSO with Microsoft Entra ID using SAML: create a federated directory using SAML setup. Most of the setup is in the Microsoft Azure portal.
- If you have a working federated directory, you can add sync capability on top of your existing setup.
- You cannot manage users manually or with other sync methods once you set up Microsoft Entra ID Sync for a directory. See notes prior to sync and common questions to learn more.
Overview
Add Microsoft Entra ID Sync (formerly Azure Sync) to any directory in the Adobe Admin Console to automate user management. It uses the SCIM protocol and gives you control over the users and groups sent to Adobe. Microsoft Entra ID users synchronized with the Adobe Admin Console are unique and can be assigned to one or more product profiles.
After you set up Microsoft Entra ID Sync, Microsoft Entra ID sends data to the Adobe Admin Console based on the directory's user and group provisioning. The directory details appear in the Settings section of the Adobe Admin Console.
Benefits of Microsoft Entra ID Sync
The key advantages of Microsoft Entra ID Sync with your directory in the Adobe Admin Console are:
- Manage everything in Microsoft Entra ID.
- Control what data is sent to Adobe.
- Avoid setting up another service or API.
- Customize Microsoft Entra ID user attribute mapping.
- Add sync to previously configured directories.
- Add sync to directories set up for any identity provider.
- Onboard and offboard users easily using Microsoft Entra ID.
Prerequisites
To integrate Adobe Admin Console user management with Microsoft Entra ID, you need:
- A Microsoft Entra ID account with user and group data.
- Adobe products that belong to Creative Cloud for enterprise, Document Cloud for enterprise, or Experience Cloud.
- A federated directory in the Adobe Admin Console with verified domains.
Supported integration scenarios
Directory setups differ, and Microsoft Entra ID Sync supports varying scenarios that need extra steps. Use this table to follow the steps for your setup:
|
|
Method to add sync |
|
Single federated directory with one or more domains in the same Microsoft Entra ID tenant. |
Follow Add Sync steps to establish Microsoft Entra ID Sync. |
|
Multiple federated directories with one or more domains that belong to the same Microsoft Entra ID tenant. |
1. Consolidate domains into a single federated directory. 2. Follow Add Sync steps to establish Microsoft Entra ID Sync. |
|
Multiple federated directories with one or more domains that belong to different Microsoft Entra ID tenants. |
1. Follow Add Sync steps to establish Microsoft Entra ID Sync for a single directory. 2. Repeat the setup for all separate directories that require sync. |
Notes prior to sync configuration
Follow these best practices and Adobe recommendations before you set up Microsoft Entra ID Sync:
- Export the list of existing users before you add sync, to keep a record of all user accounts and provisioned licenses.
- If you set up Microsoft Entra ID SSO with OpenID Connect (OIDC), add a new Adobe Identity Management application in the Microsoft Azure portal to set up directory sync.
- If you set up Microsoft Entra ID SSO with SAML, use the existing Adobe Identity Management application to configure directory sync. Follow the steps in the Microsoft document to configure automatic user provisioning.
- Microsoft Entra ID Sync decouples email from username. Users can use a different email and username to validate sign-in and access Adobe products and services. Follow the steps in the Microsoft document to customize the user provisioning attribute mapping.
- If you integrate sync with a directory that has Federated ID users, verify that their username field format matches the user principal name (UPN) in Microsoft Entra ID before the initial sync. If these values do not match, the Admin Console treats it as a new account and creates duplicate records. Update the attribute mapping so the synced values match the Admin Console user profiles, which updates the accounts on the next sync.
- Microsoft Entra ID Sync needs an Admin Console with at least one federated directory and domain. If the Admin Console with sync (owning Console) is in a trust relationship with other Admin Consoles (trustee Consoles), the trustees must use another method, such as the User Sync Tool, the User Management API, or bulk CSV upload, to create, manage, and license Federated ID users. To add a user to a trustee Console for license provisioning, first add the user to the owning Console.
- If your organization uses the User Sync Tool or a User Management API integration, first pause the integration. Then add Microsoft Entra ID Sync to automate user management from Microsoft Entra ID. After sync is configured and running, you can remove the User Sync Tool or User Management API integration.
- Your organization must have a Premium (P1 or P2) or Microsoft 365 (E3 or A3) subscription with Microsoft Entra ID to use group-based assignment. It lets you choose specific groups and users to sync to the Adobe Admin Console. Organizations without these subscription levels can sync all users and groups at once. The system syncs all users and groups automatically and generates an Adobe Federated ID for the synced users.
- To move a domain to or from a directory set up with sync, first enable editing for the directory temporarily. Move the domain, then disable editing.
- Microsoft Entra ID Sync does not sync users from groups with the HiddenMembership attribute. To sync specific users, create a group in Microsoft Entra ID and copy the users to the new group.
Add Microsoft Entra ID Sync to a federated directory
Add Microsoft Entra ID Sync to an Adobe Admin Console federated directory that has the required domains linked. To add sync to an established federated directory:
On the Settings tab of the Adobe Admin Console, go to Directory Details and select Sync. Select Add Sync.
Select the Sync users from Microsoft Azure card and select Next.
In the Microsoft Azure portal
Leave the Admin Console window open for reference and open the Microsoft Azure portal in a separate browser. Follow the steps in the Microsoft document to configure automatic user provisioning.
- You can sync nested groups from Microsoft Entra ID. Nested groups are not synced automatically when the parent group is added to the sync scope, so add nested groups to the scope to include them.
- Group-based assignment needs a Premium (P1 or P2) or Microsoft 365 (E3 or A3) subscription with Microsoft Entra ID, which lets an administrator choose specific groups and users to sync. Organizations without these subscription levels can sync individual users, or all users and groups, to the Adobe Admin Console.
After setup, Microsoft Entra ID processes and sends data for provisioning in Adobe. Review more instructions in the Microsoft application management tutorials.
In the Adobe Admin Console window, select the box to confirm authorization of Adobe access and completed setup in Microsoft Entra ID. Then select Done.
Go back to the Directory details and select Sync. Sync Source appears.
Microsoft Entra ID Sync is integrated with your directory, but has not started. To start sync, select Go to Settings and edit the sync settings.
Edit Sync settings
A System Administrator can update settings for the Sync Source after setup. Select Go to Settings from the Directory settings > Sync tab. Setting options include:
- Allow editing synced data in Admin Console: After Microsoft Entra ID Sync is established, all users and sync-created groups in a directory go under sync management automatically. After you enable editing, you can edit synced data in the Admin Console for a brief period. Edits during this time do not affect user information in Microsoft Entra ID, and change requests from your identity provider overwrite them.
By default, edit synced data from the identity provider and let the changes propagate through sync. We do not recommend changing data manually in the Admin Console unless absolutely necessary.
- Sync status: Instructs sync to reject change requests from Microsoft Entra ID. Once the sync status is Off, changes in Microsoft Entra ID are not pushed to the Adobe Admin Console.
- Edit user sync configuration: Redirects you to the configuration instructions to edit user sync. Use this if the dialog closes before you complete setup, or if you must change settings in Microsoft Entra ID after the initial configuration.
Remove sync
Administrators can remove sync from a federated directory in the Admin Console. Removing sync leaves the directory and its associated domains, user groups, and users intact, and removes read-only mode from the directory and its users and groups.
To remove sync from a directory, select Go to Settings from the Directory settings > Sync tab, then Remove Sync. This permanently removes the sync setup from the Admin Console. If needed, you can reestablish sync with the same or a different directory.
Domains cannot be moved to or from a directory managed by Microsoft Entra ID Sync within the same organization. Once sync is removed from the source or target directory, a domain from that directory can be moved to another target directory, and domains from other source directories can be moved into the directory that is no longer managed by sync.
Disable users and groups
Setting up Microsoft Entra ID Sync creates new federated user accounts and syncs users to the Adobe Admin Console. Administrators can also deprovision users and groups added through sync, using these three methods in the Microsoft Azure portal:
- Remove the user from all synced groups in Microsoft Entra ID.
- Soft delete the user from Microsoft Entra ID.
- Remove all groups that the user is part of from the provisioning scope in Microsoft Entra ID.
These three operations disable users in the Adobe Admin Console. A disabled user can no longer sign in and shows as Disabled in the Directory Users list. Microsoft Entra ID Sync continues to manage a user who has been deprovisioned by one of these methods. Neither the user's account nor cloud-stored assets are removed from the organization.
Remove a user and associated data from the Admin Console: Select Go to Settings from the Directory settings > Sync tab and select Enable editing. Then go to Users > Directory Users, and choose the user to permanently delete the account.
Once editing is enabled, you can edit synced data for 1 hour before it is automatically disabled. Select Disable editing immediately after you remove a user, so the Admin Console reflects Microsoft Entra ID changes.
If you permanently delete a user, they are removed along with all cloud-stored assets associated with that user. The user and the assets cannot be recovered.
Quarantine policy
Adobe and Microsoft have a quarantine policy to handle numerous error calls during sync operations.
The Microsoft Entra ID provisioning service monitors the health of your configuration and places unhealthy apps in a quarantine state. If most or all calls against the target system consistently fail because of an error, for example invalid admin credentials, the provisioning job is marked as in quarantine. While in quarantine, the frequency of incremental cycles is gradually reduced to once per day. The job is removed from quarantine after all errors are fixed and the next sync cycle starts. If the job stays in quarantine for more than four weeks, it is disabled and stops running. Learn more about provisioning in quarantine status within Microsoft Entra ID.
Adobe's service independently monitors sync health to detect when the error rate passes a threshold in a set time. A minimum number of error requests that meets the threshold triggers temporary quarantine, which rejects all calls and update requests from Microsoft Entra ID for a time, after which calls are accepted again for sync retry. If error calls persist, the sync is placed on temporary probation for an extended time in quarantine. If Adobe initiates the quarantine, it can lead to a subsequent quarantine with Microsoft because of the rejected calls, which count toward error rates in Microsoft Entra ID. Adobe reserves the right to update the quarantine parameters based on ongoing data analytics.
Common error messages
A set of common error messages appears when you manage Microsoft Entra ID Sync. Understanding the cause of each message helps with troubleshooting. Learn more about monitoring your deployment within Microsoft Entra ID.
Troubleshoot sync issue
As the Adobe Admin Console uses Microsoft's sync service, all sync issues are troubleshot within Microsoft Entra ID. Refer to Microsoft's configuration instructions to solve common issues. If you cannot find a solution, contact Microsoft Support. Follow these steps to diagnose a sync issue:
Confirm your user and group setup. Make sure you configured the users and groups per the setup instructions:
Confirm mapping of the user details: Microsoft documentation.
Monitor your provisioning application to uncover issues that may affect sync. If users do not appear in the provisioning logs, they may be out of scope. If the logs show an issue, fix it so the user can sync. Microsoft documentation.
PowerShell extensions: use the AzureAD PowerShell module to identify issues with the user's directory record. Confirm the user data with these PowerShell commands. If you need time, enable editing mode in the Admin Console to make temporary changes:
Install-Module AzureAD
Connect-AzureAD -Credential (Get-Credential)
Get-AzureADUser -ObjectId <user's email address> | FL
Allow editing synced data in Admin Console: after you enable editing, you can edit synced data in the Admin Console for a brief period. Edits during this time do not affect user information in Microsoft Entra ID. Later, your identity provider's change requests overwrite these brief changes.
Manage existing user accounts
Additional steps are required to convert all existing non-Federated ID users to Federated ID type.
Do not assign any products to the synced federated users during the identity switch. Do it right after syncing, but before any product assignment.
Users with an existing non-Federated ID account in the Admin Console can be migrated to a Federated ID account after Microsoft Entra ID Sync is established. Once converted, Microsoft Entra ID pushes these accounts to the Adobe Admin Console. To make sure cloud-stored assets are migrated to the user's new identity type, follow these steps:
Set up Microsoft Entra ID Sync for users who already have a non-Federated ID in the Adobe Admin Console. Any user with an existing non-Federated ID now has both a non-Federated ID and a Federated ID in the Adobe Admin Console.
Follow the steps in Edit Identity Type by CSV to change non-Federated ID users to Federated ID type. Match these details:
- Match Username and Email with the Username (UserPrincipalName) fields in Microsoft Entra ID.
- Match First Name and Last Name with the corresponding fields in Microsoft Entra ID.
When the user signs in with the new Federated ID, they are prompted to migrate cloud-stored assets to the new account.