Get answers to frequently asked questions about configuring SCIM sync.
Only Federated ID user accounts are supported for SCIM sync. Learn more about the identity type options here.
SCIM pulls the following information from the Active Directory:
- FirstName
- LastName
- Username
- Country Code
No, Adobe Admin Console does not offer provisioning logs. Check provisioning logs in your sync provider's portal for diagnostic information
The SCIM protocol allows you and your identity provider to control the flow of data. If the sync provider doesn't sync data to Adobe, check provisioning logs for the Adobe application inside the sync provider’s portal.
If your user group contains more than 50,000 users, you may experience sync failure depending on the sync provider. If you experience any sync failures, do one of the following:
- Reduce your user group size to fewer than 50,000
- Use alternative solutions for user provisioning and license assignment (Automatic account creation, Automatic assignment rules, Request Access)
- Configure your sync provider to reduce the size of a single request to less than 50,000.
Ensure that the values passed to user attributes by sync match the values in user profiles in Adobe Admin Console. Check the provisioning logs to find the attributes passed by the sync provider.
Yes. This allows users to use a different email and username value to validate sign-in and access Adobe products and services, collaborate, share files, and more.
Yes. Any updates in the sync provider are reflected in the Adobe Admin Console directory, including attributes such as FirstName, LastName, and Email.
For synced Federated ID users, the Account Status column displays either Active (user account is available for SSO login and license access and is in scope for automated sync) or Disabled (user account is not available for SSO login or license access, removed from sync scope, but cloud-stored assets remain available).
Edit identity type to Federated ID for existing users in your organization.
Yes, you can turn off or remove SCIM sync from a federated directory. This removes the automated sync but leaves the directory, its domains, and its users intact. When removing sync, turn off User Provisioning for the former sync provider to prevent the sync provider from quarantining the directory.
By default, when users are no longer managed through the sync provider, they are only disabled to avoid accidental data loss. To permanently remove users, enable editing synced users in the Sync tab, then remove them from the directory users list.
Check the impacted users' email addresses. The error occurs if the email address:
- exceeds 60 characters.
- is missing the @ symbol.
- contains illegal characters.
Yes. You can add SCIM sync to both new and existing directories with SSO authentication set up.
No. You can associate a directory with only one sync setup type.
SCIM sync provides user management only for the primary Admin Console in a primary-trustee relationship. Trustee Admin Consoles can use SSO login with the federated directory, but must use a separate user management method (CSV manual upload, User Sync Tool, or User Management API).
Your sync provider controls the sync cycle and the provisioning rate. The initial cycle takes longer to sync all users and groups defined in scope. You cannot speed up the automated sync cycle from the Adobe Admin Console.