Manage authentication settings

Last updated on Aug 3, 2026

Explore security controls for password strength, verification methods, and session management for your organization.

Authentication settings in the Adobe Admin Console control how users verify their identity and access Adobe products and services. Configure these policies to balance security and usability.

System Admins configure authentication settings in the Admin Console at Settings > Privacy and Security > Authentication Settings. The policies you set here work with your identity settings to strengthen security.

Password settings

Password policies define the minimum security requirements for user credentials. These policies apply to Enterprise ID and Adobe ID users in your organization. Federated ID users authenticate through your identity provider, where you control password requirements.

All Adobe accounts include an automatic lockout mechanism. When the system detects multiple failed login attempts in quick succession, it temporarily locks the account to prevent brute force attacks.

You can select from three authentication levels, each offering a different balance between security and user convenience:

Level

Password requirements

User experience

Low

Minimum complexity

Faster account creation, easier to remember

Medium

Moderate complexity with character variety

Balance of security and usability

High

Strong complexity with length and character requirements

Maximum security may require password managers

When you select an authentication level, the Admin Console applies it to future password creation and reset operations.

2-step verification

Two-step verification adds a second layer of authentication beyond the password. Users who enable this feature must provide both their password and a verification code when signing in to Adobe products.

Note

Two-step verification applies only to Enterprise ID and Adobe ID users, not to Federated ID users. However, you can enforce two-step verification for them through your identity provider.

Individual users can turn on two-step verification in their Adobe account settings. As a System Admin, you can enforce this requirement organization-wide, preventing users from turning it off.

Note

Adobe recommends enforcing two-step verification in your organization.

When you enforce two-step verification, users receive an email notification. The first time they sign in after enforcement begins, Adobe prompts them to provide a phone number for account recovery. Users who previously set up two-step verification continue using their existing configuration but can no longer unenroll.

Enforcement of two-step verification may take up to 24 hours to apply to all users in your organization.

Social login policy

Social login allows users with Adobe IDs to authenticate using credentials from providers such as Google, Facebook, or Apple. As an admin, you control which social login providers your organization permits.

When you disable a social login provider, existing Adobe ID users must create a password for their Adobe ID on their next sign-in attempt. Adobe notifies users when they attempt to use a disabled provider and guides them through password creation.

Social login policy applies only to Adobe ID users. Enterprise ID users always authenticate with Adobe-managed credentials, and Federated ID users always use your configured single sign-on provider.

IP-based access

IP-based access restricts access to specific products and services to specific public IP addresses. It prevents users from signing in or switching profiles when connecting from outside your approved network locations.

You configure IP-based access by adding public IP addresses to an allowed list on the Authentication Settings page in the Admin Console. Once allowed, users connecting from addresses not on your list cannot authenticate to Adobe products, and any restricted profile on their device becomes disabled.

Enabling IP-based access does not force currently signed-in users to log out. The restriction applies when users attempt to sign in or switch between Business and Personal profiles. Learn how to limit product access by IP addresses to enhance your organization's security.

Session duration controls

Advanced authentication settings let you define how long users remain authenticated across Adobe applications. These controls affect all user sessions across all devices and platforms.

Maximum session life

Maximum session life determines how long users can remain signed in before Adobe requires them to reauthenticate. When the specified duration expires, users must provide their credentials again to continue working. This setting applies universally across all Adobe apps.

Maximum idle time

Maximum idle time defines the period of inactivity before Adobe automatically signs users out. Idle time tracking monitors user interaction with Adobe web applications only, including:

  • Creative Cloud Web
  • Adobe Experience Cloud
  • Adobe Express
  • Adobe Stock
  • Adobe Color
  • Adobe Fonts
  • Creative Cloud Assets
  • Behance Portfolio
  • Acrobat.com

Desktop applications do not participate in idle time tracking.

Tip

Adobe recommends avoiding short session policies unless you require stricter security measures.

When a user belongs to multiple organizations with different session policies, Adobe applies the most restrictive values. For example, if one organization sets a 12-day maximum session life and another sets a 9-day maximum, the user must reauthenticate every 9 days.