-
Setup and onboarding
- Explore Adobe Admin Console
- Sign-in and access
-
Plan your deployment
- Basic concepts
- Deployment Guides
-
Deploy Creative Cloud for education
- Education Deployment Home
- Education Deployment K-12 Onboarding Wizard
- Education Deployment Simple Setup
- Education Deployment Setup With User Sync
- Education Deployment Setup with Roster Sync
- Education Deployment Key licensing Concepts
- Education Deployment Setup Concepts
- Education Deployment Quick Tips
- Approve Adobe apps in Google Admin Console
- Enable Adobe Express in Google Classroom
- Integrate Adobe Creative Cloud and Adobe Express with Canvas LMS
- Adobe Creative Cloud & Blackboard Learn
- Configuring SSO for District Portals and Learning Management Systems
- Roster syncing for license assignment with the Adobe Admin Console
- Kivuto FAQ
- Primary and Secondary Institution Eligibility Guidelines
-
Licensing
- Licensing overview
- Licensing types
-
Set up your organization
- Identity overview
- Set up identity and Single Sign-On
- Set up organization with Enterprise ID
- Setup Azure AD federation and sync
- Set up Google Federation and sync
- Configure Microsoft AD FS for use with Adobe SSO
- Configuring SSO for District Portals and Learning Management Systems
- Set up organization with other Identity providers
- SSO common questions and troubleshooting
- Set up Frame.io for enterprise
-
Identity and SSO
- Set up identity
- Integrate with Microsoft Entra
- Integrate with Google Sync
- Integrate with other SSO providers
- Troubleshoot
-
Manage your organization setup
- Manage existing directories and domains
- Enable automatic account creation
- Domain Enforcement for restricted authentication
- Set up organization via directory trust
- Migrate to a new authentication provider
- Asset settings
- Manage authentication settings
- Limit product access by IP addresses
- Privacy and security contacts
- Console settings
- Manage encryption
-
Directories, domains, and access
-
Directories and domains
- Create a directory for SAML identity providers
- Verify domain ownership
- Set up domains for directory authentication
- Move domains across directories
- Encrypted and trusted directory domain transfers
- Move directories between Admin Consoles
- Delete directories and domains
- Automatic account creation overview
- Enable automatic account creation
- Automatic federated account creation FAQ
- Domain enforcement
- Directory trusting
-
Directories and domains
-
Manage users
- Adobe Admin Console users
- Administrative roles
- Assign user roles for granular access control
- How to create custom roles
- Manage Frame.io account roles in Adobe Admin Console
- User management strategies
- Assign a license to teams user
- Team Management: Creative Cloud desktop app, Acrobat, Express
- Adobe's matching service
- Edit user identity type
- Manage user groups
- Manage directory users
- Exclude specific users from domain enforcement
- Manage developers
- Migrate existing users to the Adobe Admin Console
- Migrate Frame.io user management to the Adobe Admin Console
- Admin roles and hierarchy
- Enterprise admin permissions matrix
-
Settings
- Asset settings
- Manage encryption
-
Manage products and entitlements
-
Manage products and product profiles
- Manage products on Admin Console
- Add products and licenses
- Manage product profiles for enterprise users
- Manage automatic assignment rules
- Adobe Express Photos FAQs for administrators
- Assign users to Firefly custom models
- Enable Shared Credits for your organization
- Manage product requests
- Manage self-service policies
- Manage app integrations
- Manage product permissions in the Admin Console
- Single App | Creative Cloud for enterprise
- Manage Shared Device licenses
-
Manage products and product profiles
-
User management
- Understand user management
- Manage users and groups
- Manage admins
- Manage user roles
- Migrate users
-
Get started with Global Admin Console
- Adopt global administration
- Select an organization in the Global Admin Console
- Manage organization hierarchy
- Manage product profiles
- Manage administrators
- Manage user groups
- Create license assignment reports for multiple organizations
- Update organization policies
- Manage policy templates
- Allocate products to child organizations
- Execute pending jobs
- Download audit logs and export reports
- Export or import organization structure and product allocations
-
Products and entitlements
- Manage products
- Manage product profiles
- Special programs plans
- Manage entitlements
- Manage automatic assignment
- Manage product access
- Manage self-service policies
- Manage app integrations
- Frame.io integration
- Manage product permissions
-
Manage storage and assets
- Storage
- Manage projects
- Asset migration
- Reclaim assets from a user
- Student asset migration | EDU only
- Manage storage and assets
-
Manage services
- Manage services in the Admin Console
- Configure services
- Optional services
- Adobe Stock
- Enable Shared Credits for your organization
- Custom fonts
-
Adobe Asset Link
- Adobe Asset Link
- Adobe Asset Link Overview
- Create user group for Adobe Asset Link
- Configure Experience Manager Assets as a Cloud Service
- Deploy Adobe Asset Link
- Configure Adobe Experience Manager 6.x Assets for Adobe Asset Link
- Manage assets using Adobe Asset Link
- Adobe Asset Link for Adobe XD
- Troubleshoot Adobe Asset Link
- Known issues with Adobe Asset Link
- Adobe Acrobat Sign
-
Deploy apps and updates
- Overview
-
Create packages
- Packaging apps via the Admin Console
- Create Named User Licensing Packages
- Manage pre-generated packages
- Manage Packages
- Customize packages
- Deploy Packages
- Manage updates
- Adobe Update Server Setup Tool (AUSST)
- Adobe Remote Update Manager (RUM)
-
Deploy apps and updates
- Prepare for deployment
- Manage pre-generated packages
- Create packages
- Customize end-user experience
- Deploy packages
- Use third-party deployment tools
-
Manage Shared Device Licensing (SDL)
- Shared Device Licensing overview
- Deploy Shared Device Licensing
- Manage SDL profiles and user access
- Activate shared device licenses
- Use the Shared Device Licensing toolkit
- Recover shared device licenses
- Shared Device Licensing identity FAQ
- Shared Device Licensing deployment FAQ
- Shared Device Licensing access FAQ
- Known issues in Shared Device Licensing
- Adobe Update Server Setup Tool (AUSST)
- Adobe Remote Update Manager (RUM)
- Troubleshoot
-
Manage your Teams account
- Manage your account
- Complimentary membership for team members
- Update payment details on your Teams account
- Download and email invoices
- Change the contract owner of your Teams account
- Change your Creative Cloud for teams plan
- Change reseller
- Cancel Creative Cloud for teams licenses
- Purchase Authorization Compliance
- Contracts and renewals
- Renewals
- Reports and logs
-
Manage contracts
- Automated expiration stages for ETLA contracts
- Switching contract types within an existing Adobe Admin Console
- Manage trials and special offers
- Complimentary membership for team members
- Creative Cloud for enterprise - free membership
- Frame.io and Creative Cloud for teams and enterprise plans
- Value Incentive Plan (VIP) in China
- VIP Select Help
-
Get started with Global Admin Console
- Get started
- Manage your organization
- Reports audit
-
Get help
- Enterprise and teams | Contact Adobe Customer Care
- Support options
- Teams | Support and Expert Sessions
-
General troubleshooting
- Microsoft Purview Information Protection support in Acrobat
- Use the Creative Cloud Cleaner tool to fix installation issues
- Fix app launch errors on Shared Device Licensing machines
- Technical support boundaries for virtualized or server-based environments
- Resolve trial and license expired errors
- Migrating to OAuth Server-to-Server Credentials
- Manage device authentication for Creative Cloud and Acrobat Pro
- Enterprise | Support and Expert Sessions
Azure Active Directory authentication and sync FAQ
Get answers to common questions about configuring Azure AD authentication and Azure Sync with federated directories.
The following are common questions about Azure AD authentication, Azure Sync configuration, and troubleshooting sync issues with federated directories. Questions are organized by setup, configuration, and troubleshooting workflows.
Azure Sync creates only Federated ID user accounts. Learn more about identity type options to understand the differences between Business ID, Enterprise ID, and Federated ID.
No, Adobe Admin Console does not offer provisioning logs. Check provisioning logs in your Azure Active Directory portal for diagnostic information. Refer to Microsoft's documentation on Provisioning logs in Azure Active Directory to learn more.
Adobe has upgraded the Azure Sync experience to provide enhanced security and privacy controls. The updated Azure Sync does not require permissions in your organization's Azure Directory to sync users to the Adobe Admin Console.
Azure Sync provides user management only for the primary Admin Console in a primary-trustee relationship. Trustee Admin Consoles can use single sign-on with the federated directory. However, they must use a separate user management method, such as CSV manual upload, the User Sync Tool, or the User Management API.
The SCIM protocol allows you and your identity provider to control the data flow. If Azure Sync doesn't sync data to Adobe, check provisioning logs for the Adobe Identity Management application inside your Azure AD Portal.
Ensure that the values passed to user attributes by sync match the values in user profiles in Admin Console. Check the provisioning logs in Azure to find the attributes passed from Azure.
Yes. This allows users to use a different email and username value to validate sign-in and access Adobe products and services, collaborate, share files, and more.
Your organization must have a Premium P1 or P2, or Microsoft 365 E3 or A3 subscription with Azure AD to use group-based assignment capabilities. This allows you to choose specific groups and users to sync to the Adobe Admin Console. Organizations without these subscription levels can only sync all users and groups at once.
Yes, you can sync nested groups from Azure AD through the Azure Sync integration. However, nested groups are not automatically synced when the parent node is added to the sync scope. You must add nested groups to the scope to be included in the automated sync.
Yes. Any updates in Azure AD are reflected in the Adobe Admin Console directory, including attributes such as FirstName, LastName, and Email.
Yes. To use Azure Sync with a directory configured with a different identity provider, you must manage your users in an Azure AD instance.
Azure AD controls the sync cycles. The initial cycle takes longer to sync all users and groups defined in scope. Subsequent cycles occur approximately every 40 minutes as long as the Azure AD provisioning service is running. You cannot speed up the automated sync cycle from the Adobe Admin Console.
For Federated ID users synced with Azure Active Directory, the Account Status column displays either Active (user account available for SSO login and license access, in scope for automated sync) or Disabled (user account not available for SSO login or license access, removed from sync scope but cloud-stored assets remain available).
No, you cannot run Azure Sync alongside any other form of user management tool. If your organization uses User Sync Tool or a UMAPI integration, first pause the alternate sync, then follow the steps to set up Azure Sync. The User Sync Tool or UMAPI integration can be removed completely once Azure Sync is configured and running.
Edit identity type to Federated ID for existing users in your organization.
Review common error messages in Azure AD to troubleshoot sync issues. Learn more about monitoring your deployment within Azure AD. Follow the troubleshooting sync for more methods.
Yes, you can disable or remove Azure Sync from a federated directory. This removes the automated sync but leaves the directory, its domains, and its users intact. When removing sync, turn off User Provisioning for the former sync in Azure AD to prevent quarantine of the directory by Azure AD.
By default, when users are no longer managed through Azure Sync, they are only disabled to avoid accidental data loss. To permanently remove users, enable editing synced users in the Sync tab, then remove them from the directory users list.
Check the impacted user's email address. The error occurs if the user's email address is longer than 60 characters, is missing the @ symbol, or contains illegal characters.
Azure Sync pulls FirstName, LastName, Username, Email, and Country Code from your Azure Active Directory to create and update user accounts in Adobe Admin Console.
For additional configuration guidance, see Set up Azure Sync.