Adobe Single Sign On Configuration with Rapid Identity

Last updated on Dec 16, 2024

Adobe Single Sign On Configuration with Rapid Identity

Overview

The Adobe Admin Console allows a system administrator to configure domains which are used for login via Federated ID for Single Sign-On (SSO). Once the domain is verified, the directory containing the domain is configured to allow users to log in to Creative Cloud. Users can log in using email addresses within that domain via an Identity Provider (IdP). The process is provisioned either as a software service which runs within the company network and is accessible from the Internet or a cloud service hosted by a third party that allows for the verification of user login details via secure communication using the SAML protocol.

One such IdP is Rapid Identity. To use Rapid Identity, you need a server that is accessible from the Internet and has access to the directory services within the corporate network. This document describes the process to configure the Admin One Console and a Rapid Identity server to log in to Adobe Creative Cloud applications and associated websites for Single Sign-On.

Prerequisites

Before configuring a domain for single sign-on using Rapid Identity, ensure that the following requirements are met:

  • The server is accessible from user workstations (for example, via HTTPS)
  • All Active Directory accounts to be associated with a Creative Cloud for Enterprise account have an email address listed within Active Directory.

Configure Rapid Identity

Before you begin, create a Federated ID directory, selecting Other SAML Providers as the identity provider. Download the Adobe metadata file from the Add SAML Profile screen.

Sign in to Rapid Identity as an Administrator and select IDP Configuration under Configuration.

Select the Register New Service provider menu.

Provide a name to the Service provider and paste the Adobe metadata file content. 

Set the configuration in SSO Advanced Settings and  ECP Advanced Settings.

Go to Edit IDP Attributes and add the attributes for FirstName, LastName, and Email.

Go to Name ID Attributes and add the attribute.

Select Save.

Upload IdP metadata file to Adobe Admin Console

To update the latest certificate to the Adobe Admin Console, return to the Adobe Admin Console. Upload the certificate downloaded from Rapid Identity to the Add SAML profile screen and click Done.

Test your setup

Check the user access for a user whom you have defined in your own identity management system and in the Adobe Admin Console, by logging in to the Adobe website or the Creative Cloud desktop app.

If you encounter problems, see our troubleshooting document.

If you need assistance with your single sign-on configuration, navigate to Adobe Admin Console > Support to contact Adobe Customer Care.

Additional information

If you modify the portal, ensure you select the Trigger Service Reload and Trigger Web Reload options afterward for the changes to take effect.