Set up SCIM sync for your federated directory

Last updated on Sep 30, 2026

Automate user management for your Adobe Admin Console federated directory. Add any SCIM 2.0-compliant identity provider as your sync provider.

Overview of SCIM sync

SCIM Sync lets you automate user management between your sync provider and Adobe Admin Console. It automates user provisioning and management, eliminates manual updates, and maintains consistent identities across systems. Your sync provider can be any SCIM 2.0-compliant identity provider. Add SCIM Sync to any federated directory in the Adobe Admin Console, regardless of which identity provider manages authentication.

After configuration, your sync provider automatically sends changes to user data in the Adobe Admin Console based on the directory's user and group provisioning. The sync manages user accounts and updates user attributes. Synced users and user groups can be assigned to product profiles to provision licenses.

Prerequisites

To add SCIM Sync, you need:

  • A federated directory in the Adobe Admin Console with at least one verified or guest domain linked to it.
  • A sync provider that supports SCIM 2.0
  • System Administrator role in the Adobe Admin Console and provisioning administrator rights in your sync provider
Note

Pause the User Sync Tool or UMAPI integrations before adding SCIM Sync. After SCIM Sync is configured and running, remove the previous integration method to avoid conflicts.

Set up SCIM sync

Sign in to the Adobe Admin Console, and go to Settings > Directory Details for your federated directory.

Select the Sync tab, then select Add Sync.

Select Sync users from other identity providers, then select Next.

Copy the SCIM base URL and the API token generated by the Admin Console, then keep the Admin Console window open. Treat the API token like a password and do not share it outside of the sync setup process.

In a separate browser, open the sync provider portal and follow the sync provider-specific steps to configure automatic user provisioning. Refer to your sync provider's technical documentation for setup instructions. Here are some widely used resources:

Paste the SCIM base URL and API token into the relevant fields in your sync provider. The field labels vary by sync provider. Match them as follows:

Adobe Admin Console

Relevant fields

SCIM base URL

  • SCIM connector base URL
  • Tenant URL
  • Base URL

API token

  • Secret token
  • Bearer token
  • SCIM bearer token

After completing all steps in your sync provider, return to the Adobe Admin Console. In the Adobe Admin Console window, select the box to confirm authorization of Adobe access and complete setup in your sync provider. Then select Done.

Confirm that SCIM Sync appears under Directory Details > Sync, and verify that the configuration is successful.

Edit SCIM sync

System Administrators can update sync settings after initial setup by selecting Go to Settings from the Directory settings Sync tab.

Here are the available settings:

  • Allow editing synced data in Admin Console: Temporarily enables manual editing of synced user data in Adobe Admin Console. Changes made during this period don't affect Admin Console data and are overwritten by subsequent sync operations.
  • Sync status: Controls whether SCIM Sync accepts changes from the sync provider Admin Console. When sync status is off, changes made in the sync provider Admin Console don't push to the Adobe Admin Console.
  • Edit user sync configuration: Redirects you to configuration instructions to modify sync setup.
Caution

By default, synced user data can only be edited in your identity provider, and changes sync to the Adobe Admin Console. Enable manual editing only when necessary.

Remove SCIM sync

Removing sync from a directory leaves the directory, domains, user groups, and users intact while removing read-only restrictions.

In the Adobe Admin Console, navigate to Directory settings > Sync and select Go to Settings.

Select Remove Sync to delete the sync configuration permanently.

In the sync provider admin console, turn off auto-provisioning for the Adobe SAML app to prevent quarantine issues.

After removal, you can reestablish sync with the same or a different directory if needed.

Note

You cannot move domains to or from a directory managed by SCIM sync. Once sync is removed from the source or target directory, a domain from that directory can be moved to another target directory, and domains from other source directories can be moved into the directory that is no longer managed by sync.

De-provision users

SCIM Sync enables user deprovisioning through the following methods in the sync provider admin console:

  • Delete or suspend users from the sync provider
  • Remove all groups associated with users from the provisioning scope
  • Remove users from all synced groups in the sync provider

These actions disable users in the Adobe Admin Console. Disabled users cannot sign in and appear as Disabled in the Directory Users list. The user account and cloud-stored assets remain in the organization.

Note

There may be more actions available for user deprovisioning depending on your sync provider.

Remove users and data

To permanently delete a user and associated data, you must enable editing of synced data before removal.

Alert

Deleting a user permanently removes the account and all cloud-stored assets. This action cannot be reversed.

In the Adobe Admin Console, navigate to Directory settings > Sync, then select Go to Settings.

Select Enable editing to allow temporary manual changes.

Navigate to Users > Directory Users and select the user from the list.

Select the option to delete the user account permanently.

Return to Directory settings > Sync > Settings and select Disable editing.

Disable editing immediately after removing a user to ensure the Adobe Admin Console accurately reflects changes in the sync provider.

Manage sync

Synced directories are read-only by default. To allow manual edits, go to Directory Details > Sync > Settings, and enable editing of synced data. Manual changes can be overwritten on the next sync.

Removing sync leaves the directory, domains, users, groups, and license assignments intact and only removes the read-only restriction. It does not delete users or groups.

Users are disabled, not deleted, when removed from the provider's scope. Removing a user group does not remove its users; they retain access to any products assigned through that group’s profiles.