Identity Types
Understand how identity types control user authentication, data ownership, and security in your organization.
Your choice of identity type determines who controls user credentials, how authentication works, and where user data resides. It shapes your organization's security model, affects how easily you can integrate Adobe products with existing directory services, and defines your administrative responsibilities for password management and account lifecycle management.
Adobe Admin Console supports three identity types for enterprise and teams customers: Federated ID, Enterprise ID, and Adobe ID. Each offers different levels of organizational control and integrates with your existing infrastructure in different ways.
How identity types differ
Identity types control three critical aspects of user account management: authentication method, credential ownership, and data control. Organizations using Federated ID or Enterprise ID create and manage accounts centrally, while Adobe ID accounts are created and controlled by individual users.
The identity type you select determines which authentication features you can use. Federated ID enables Single Sign-On through your existing identity provider, while Enterprise ID uses Adobe-managed authentication with organization-controlled password policies.
Identity type comparison
The following table compares the three identity types across key functional areas to help you evaluate which model aligns with your organization's requirements.
|
|
Federated ID |
Enterprise ID |
Adobe ID |
|
Key offerings |
Created, owned, and managed by the organization. The organization manages user-credentials and uses Single Sign-On (SSO) via a SAML2 identity provider (IdP). |
Created, owned, and managed by the organization. The organization retains exclusive rights to create user accounts on verified domains. |
Created, owned, and managed by the end user. Adobe handles authentication, and the end user manages identity. Depending upon the storage model, users or businesses retain control over files and data. Adobe ID accounts are created on unverified, public, or trusted domains. |
|
Account and data ownership |
Organization-owned and controlled |
Organization-owned and controlled |
Organization-owned for Enterprise storage and user-owned for User storage |
|
Security and monitoring |
|
|
|
|
Reset password |
Not supported |
||
|
Creative Cloud for enterprise and Document Cloud for enterprise |
Supported |
Supported |
Supported |
|
Creative Cloud for teams and Document Cloud for teams |
Not supported |
Not supported |
Supported |
|
Experience Cloud |
Supported |
Supported |
Supported |
|
Recommended for |
|
|
|
|
Getting started |
Password policy for Creative Cloud for teams is the same as that for Creative Cloud for individuals.
Adobe ID accounts are created on unverified public or trusted domains. Adobe ID users authenticate with their Adobe ID credentials or by their owning organization's authentication model (SSO, 2FA, and so on). In such scenarios, users are redirected to the owning organization's SSO page. After authentication, users may need to choose a business profile.
Federated ID
Federated ID gives you the highest level of control by delegating authentication to your organization's existing identity provider. Users sign in through your SSO system using the same credentials they use for other enterprise applications.
This identity type works with SAML2-compatible identity providers and maintains your organization's centralized authentication policies. You control password requirements, multi-factor authentication rules, and session management through your IdP rather than managing these separately for Adobe products.
Because authentication occurs entirely within your infrastructure, Federated ID users cannot reset passwords through Adobe systems. All credential management is handled through your organization's standard processes.
Enterprise ID
Enterprise ID provides organization-controlled accounts without requiring SSO infrastructure. Adobe hosts the authentication system, but your organization owns the accounts and controls who can create them on your verified domains.
You must demonstrate domain ownership by completing DNS verification before creating Enterprise ID accounts. Once verified, only your organization can create accounts on those domains, preventing unauthorized parties from creating accounts.
Enterprise ID supports organizations that want centralized account control without integrating an external identity provider. Users reset passwords through Adobe's system, and you can configure password policies to meet your security requirements.
Adobe ID with Business Profile
When your organization uses the Enterprise Storage Model, Adobe ID users access business resources through a Business Profile while maintaining their personal Adobe ID. This dual-profile model separates personal assets from organization-controlled content.
The Business Profile links the user's Adobe ID authentication to your organization's entitlements and storage. Your organization controls business data and product assignments, while users retain control over their Adobe ID credentials and any personal content.
Adobe ID accounts work with any email domain, including public domains such as Gmail or Outlook. This flexibility makes them suitable for teams organizations or scenarios where domain ownership verification isn't practical.
Choosing an identity type
Consider these factors when selecting an identity type:
Choose Federated ID if:
- Your organization already uses an enterprise identity provider
- You need to enforce SSO across all business applications
- Centralized authentication management is a security requirement
- You want users to access Adobe products with existing corporate credentials
Choose Enterprise ID if:
- You can verify ownership of your email domains
- You want organization-controlled accounts without implementing SSO
- Your organization prefers Adobe-managed authentication
- Centralized account lifecycle management is important
Choose Adobe ID if:
- You're managing a Creative Cloud for Teams organization
- Users need to maintain personal ownership of their accounts
- Your organization doesn't own the email domains users will use
- You need flexibility with public email domains
If your organization hasn't been updated to Adobe's Enterprise Storage Model and you're still using Adobe IDs for individuals, your users' data ownership and admin capabilities may differ from those described in this article. Contact Adobe Customer Care for guidance on storage model transitions.