Authenticate your users with Microsoft Entra ID

Last updated on Sep 1, 2025

Authenticate your users quickly using OpenID Connect (OIDC). You can also add Microsoft Entra ID Sync (formerly Azure Sync) to directories set up with Microsoft Entra ID to automate user management.

Prerequisites

To integrate the Adobe Admin Console with Microsoft Entra ID, you need:

  • Microsoft Entra ID as the identity provider.
  • One or more of these products: Creative Cloud for enterprise, Document Cloud for enterprise, or Experience Cloud.
  • Domains associated with Microsoft Entra ID must be unclaimed in the Adobe Admin Console. Withdraw any pending domain claims before you begin.
Note

If your identity provider is Microsoft Entra ID and you do not have a federated directory in the Adobe Admin Console, set up federation in one of these ways:

  • OpenID Connect (OIDC): create a federated directory in seconds via OIDC. Most of the setup is in the Adobe Admin Console.
  • SSO with Microsoft Entra ID using SAML: create a federated directory using a SAML setup. Most of the setup is in the Microsoft Azure portal.

 

Create a directory

Once the Microsoft admin portal is set up and ready, do the following:

Sign in to Adobe Admin Console and select Settings. On the Identity page, select Create Directory

On the Create a Directory screen, enter a name for the directory, select the Federated ID card, and select Next.

Select Microsoft Azure Active Directory and then select Sign in to Entra ID.

You are redirected to the Microsoft sign-in page. Sign in to the appropriate account, and you return to the Add identity provider window in the Adobe Admin Console.

Select Grant consent to continue Entra ID setup and select the appropriate Microsoft account to review the requested permissions. Then, select Accept.

Return to Adobe Admin Console, review your Entra ID information, and select Next.

Set up auto-account creation. Automatic account creation is enabled by default. It lets users without a federated account create one for their organization based on a verified email domain. When enabled for a federated directory, new users with a valid email domain in that directory can create a federated account.

If you disable automatic account creation, new users in your organization who have valid accounts with domains of this identity provider can no longer automatically create a federated account.

Select a default country from the dropdown menu in the Attribute mappings section.

Choose whether to update user information in Admin Console when users log in. Then, select Done.

Add domains via Microsoft Entra ID

Once you've linked your Adobe Admin Console directory with Microsoft Entra ID, add domains. To pull verified domains directly from the Microsoft admin portal, do the following:

In the Adobe Admin Console, navigate to Settings > Identity. Select a directory, go to the Domains tab and select Add domain.

Select an IdP (Microsoft Entra ID in this case). Then, select Sign in to Entra ID.

Sign in to the Microsoft account containing the verified domains to add to the Admin Console. Select one or more domains from the list of available domains and select Confirm.

On confirming, you're sent to the directory details view where the domains are listed under the Domains tab.

Next steps

After you've created a directory and added domains, you can start managing single sign-on operations by adding user and user group assignments to the corresponding product profiles.

If you administer user accounts in the Adobe Admin Console using Microsoft Entra ID, you can add Microsoft Entra ID Sync to the directory from the Sync tab in the directory details. Once configured, Microsoft Entra ID becomes the direct source of truth for Federated ID users' account management, keeping user data in sync with the Adobe Admin Console.

Note

Ensure that there are no domain trusts established to the domains being removed. If you want to retain these trust relationships, break them temporarily while completing the remaining steps. You can re-associate domain trusts once the domains are re-established in the Adobe Admin Console.