Azure Active Directory authentication and sync FAQ

Last updated on Aug 3, 2026

Get answers to common questions about configuring Azure AD authentication and Azure Sync with federated directories.

The following are common questions about Azure AD authentication, Azure Sync configuration, and troubleshooting sync issues with federated directories. Questions are organized by setup, configuration, and troubleshooting workflows.

Azure Sync creates only Federated ID user accounts. Learn more about identity type options to understand the differences between Business ID, Enterprise ID, and Federated ID.

No, Adobe Admin Console does not offer provisioning logs. Check provisioning logs in your Azure Active Directory portal for diagnostic information. Refer to Microsoft's documentation on Provisioning logs in Azure Active Directory to learn more.

Adobe has upgraded the Azure Sync experience to provide enhanced security and privacy controls. The updated Azure Sync does not require permissions in your organization's Azure Directory to sync users to the Adobe Admin Console.

Azure Sync provides user management only for the primary Admin Console in a primary-trustee relationship. Trustee Admin Consoles can use single sign-on with the federated directory. However, they must use a separate user management method, such as CSV manual upload, the User Sync Tool, or the User Management API.

The SCIM protocol allows you and your identity provider to control the data flow. If Azure Sync doesn't sync data to Adobe, check provisioning logs for the Adobe Identity Management application inside your Azure AD Portal.

Ensure that the values passed to user attributes by sync match the values in user profiles in Admin Console. Check the provisioning logs in Azure to find the attributes passed from Azure.

Yes. This allows users to use a different email and username value to validate sign-in and access Adobe products and services, collaborate, share files, and more.

Your organization must have a Premium P1 or P2, or Microsoft 365 E3 or A3 subscription with Azure AD to use group-based assignment capabilities. This allows you to choose specific groups and users to sync to the Adobe Admin Console. Organizations without these subscription levels can only sync all users and groups at once.

Yes, you can sync nested groups from Azure AD through the Azure Sync integration. However, nested groups are not automatically synced when the parent node is added to the sync scope. You must add nested groups to the scope to be included in the automated sync.

Yes. Any updates in Azure AD are reflected in the Adobe Admin Console directory, including attributes such as FirstName, LastName, and Email.

Yes. To use Azure Sync with a directory configured with a different identity provider, you must manage your users in an Azure AD instance.

Azure AD controls the sync cycles. The initial cycle takes longer to sync all users and groups defined in scope. Subsequent cycles occur approximately every 40 minutes as long as the Azure AD provisioning service is running. You cannot speed up the automated sync cycle from the Adobe Admin Console.

For Federated ID users synced with Azure Active Directory, the Account Status column displays either Active (user account available for SSO login and license access, in scope for automated sync) or Disabled (user account not available for SSO login or license access, removed from sync scope but cloud-stored assets remain available).

No, you cannot run Azure Sync alongside any other form of user management tool. If your organization uses User Sync Tool or a UMAPI integration, first pause the alternate sync, then follow the steps to set up Azure Sync. The User Sync Tool or UMAPI integration can be removed completely once Azure Sync is configured and running.

Edit identity type to Federated ID for existing users in your organization.

Review common error messages in Azure AD to troubleshoot sync issues. Learn more about monitoring your deployment within Azure AD. Follow the troubleshooting sync for more methods.

Yes, you can disable or remove Azure Sync from a federated directory. This removes the automated sync but leaves the directory, its domains, and its users intact. When removing sync, turn off User Provisioning for the former sync in Azure AD to prevent quarantine of the directory by Azure AD.

By default, when users are no longer managed through Azure Sync, they are only disabled to avoid accidental data loss. To permanently remove users, enable editing synced users in the Sync tab, then remove them from the directory users list.

Check the impacted user's email address. The error occurs if the user's email address is longer than 60 characters, is missing the @ symbol, or contains illegal characters.

Azure Sync pulls FirstName, LastName, Username, Email, and Country Code from your Azure Active Directory to create and update user accounts in Adobe Admin Console.

For additional configuration guidance, see Set up Azure Sync.