-
Setup and onboarding
- Explore Adobe Admin Console
- Sign-in and access
-
Plan your deployment
- Basic concepts
- Deployment Guides
-
Deploy Creative Cloud for education
- Education Deployment Home
- Education Deployment K-12 Onboarding Wizard
- Education Deployment Simple Setup
- Education Deployment Setup With User Sync
- Education Deployment Setup with Roster Sync
- Education Deployment Key licensing Concepts
- Education Deployment Setup Concepts
- Education Deployment Quick Tips
- Approve Adobe apps in Google Admin Console
- Enable Adobe Express in Google Classroom
- Integrate Adobe Creative Cloud and Adobe Express with Canvas LMS
- Adobe Creative Cloud & Blackboard Learn
- Configuring SSO for District Portals and Learning Management Systems
- Roster syncing for license assignment with the Adobe Admin Console
- Kivuto FAQ
- Primary and Secondary Institution Eligibility Guidelines
-
Licensing
- Licensing overview
- Licensing types
-
Set up your organization
- Identity overview
- Set up identity and Single Sign-On
- Set up organization with Enterprise ID
- Setup Azure AD federation and sync
- Set up Google Federation and sync
- Configure Microsoft AD FS for use with Adobe SSO
- Configuring SSO for District Portals and Learning Management Systems
- Set up organization with other Identity providers
- SSO common questions and troubleshooting
- Set up Frame.io for enterprise
-
Identity and SSO
- Set up identity
- Integrate with Microsoft Entra
- Integrate with Google Sync
- Integrate with other SSO providers
- Troubleshoot
-
Manage your organization setup
- Manage existing directories and domains
- Enable automatic account creation
- Domain Enforcement for restricted authentication
- Set up organization via directory trust
- Migrate to a new authentication provider
- Asset settings
- Manage authentication settings
- Limit product access by IP addresses
- Privacy and security contacts
- Console settings
- Manage encryption
-
Directories, domains, and access
-
Directories and domains
- Create a directory for SAML identity providers
- Verify domain ownership
- Set up domains for directory authentication
- Move domains across directories
- Encrypted and trusted directory domain transfers
- Move directories between Admin Consoles
- Delete directories and domains
- Automatic account creation overview
- Enable automatic account creation
- Automatic federated account creation FAQ
- Domain enforcement
- Directory trusting
-
Directories and domains
-
Manage users
- Adobe Admin Console users
- Administrative roles
- Assign user roles for granular access control
- How to create custom roles
- Manage Frame.io account roles in Adobe Admin Console
- User management strategies
- Assign a license to teams user
- Team Management: Creative Cloud desktop app, Acrobat, Express
- Adobe's matching service
- Edit user identity type
- Manage user groups
- Manage directory users
- Exclude specific users from domain enforcement
- Manage developers
- Migrate existing users to the Adobe Admin Console
- Migrate Frame.io user management to the Adobe Admin Console
- Admin roles and hierarchy
- Enterprise admin permissions matrix
-
Settings
- Asset settings
- Manage encryption
-
Manage products and entitlements
-
Manage products and product profiles
- Manage products on Admin Console
- Add products and licenses
- Manage product profiles for enterprise users
- Manage automatic assignment rules
- Adobe Express Photos FAQs for administrators
- Assign users to Firefly custom models
- Enable Shared Credits for your organization
- Manage product requests
- Manage self-service policies
- Manage app integrations
- Manage product permissions in the Admin Console
- Single App | Creative Cloud for enterprise
- Manage Shared Device licenses
-
Manage products and product profiles
-
User management
- Understand user management
- Manage users and groups
- Manage admins
- Manage user roles
- Migrate users
-
Get started with Global Admin Console
- Adopt global administration
- Select an organization in the Global Admin Console
- Manage organization hierarchy
- Manage product profiles
- Manage administrators
- Manage user groups
- Create license assignment reports for multiple organizations
- Update organization policies
- Manage policy templates
- Allocate products to child organizations
- Execute pending jobs
- Download audit logs and export reports
- Export or import organization structure and product allocations
-
Products and entitlements
- Manage products
- Manage product profiles
- Special programs plans
- Manage entitlements
- Manage automatic assignment
- Manage product access
- Manage self-service policies
- Manage app integrations
- Frame.io integration
- Manage product permissions
-
Manage storage and assets
- Storage
- Manage projects
- Asset migration
- Reclaim assets from a user
- Student asset migration | EDU only
- Manage storage and assets
-
Manage services
- Manage services in the Admin Console
- Configure services
- Optional services
- Adobe Stock
- Enable Shared Credits for your organization
- Custom fonts
-
Adobe Asset Link
- Adobe Asset Link
- Adobe Asset Link Overview
- Create user group for Adobe Asset Link
- Configure Experience Manager Assets as a Cloud Service
- Deploy Adobe Asset Link
- Configure Adobe Experience Manager 6.x Assets for Adobe Asset Link
- Manage assets using Adobe Asset Link
- Adobe Asset Link for Adobe XD
- Troubleshoot Adobe Asset Link
- Known issues with Adobe Asset Link
- Adobe Acrobat Sign
-
Deploy apps and updates
- Overview
-
Create packages
- Packaging apps via the Admin Console
- Create Named User Licensing Packages
- Manage pre-generated packages
- Manage Packages
- Customize packages
- Deploy Packages
- Manage updates
- Adobe Update Server Setup Tool (AUSST)
- Adobe Remote Update Manager (RUM)
-
Deploy apps and updates
- Prepare for deployment
- Manage pre-generated packages
- Create packages
- Customize end-user experience
- Deploy packages
- Use third-party deployment tools
-
Manage Shared Device Licensing (SDL)
- Shared Device Licensing overview
- Deploy Shared Device Licensing
- Manage SDL profiles and user access
- Activate shared device licenses
- Use the Shared Device Licensing toolkit
- Recover shared device licenses
- Shared Device Licensing identity FAQ
- Shared Device Licensing deployment FAQ
- Shared Device Licensing access FAQ
- Known issues in Shared Device Licensing
- Adobe Update Server Setup Tool (AUSST)
- Adobe Remote Update Manager (RUM)
- Troubleshoot
-
Manage your Teams account
- Manage your account
- Complimentary membership for team members
- Update payment details on your Teams account
- Download and email invoices
- Change the contract owner of your Teams account
- Change your Creative Cloud for teams plan
- Change reseller
- Cancel Creative Cloud for teams licenses
- Purchase Authorization Compliance
- Contracts and renewals
- Renewals
- Reports and logs
-
Manage contracts
- Automated expiration stages for ETLA contracts
- Switching contract types within an existing Adobe Admin Console
- Manage trials and special offers
- Complimentary membership for team members
- Creative Cloud for enterprise - free membership
- Frame.io and Creative Cloud for teams and enterprise plans
- Value Incentive Plan (VIP) in China
- VIP Select Help
-
Get started with Global Admin Console
- Get started
- Manage your organization
- Reports audit
-
Get help
- Enterprise and teams | Contact Adobe Customer Care
- Support options
- Teams | Support and Expert Sessions
-
General troubleshooting
- Microsoft Purview Information Protection support in Acrobat
- Use the Creative Cloud Cleaner tool to fix installation issues
- Fix app launch errors on Shared Device Licensing machines
- Technical support boundaries for virtualized or server-based environments
- Resolve trial and license expired errors
- Migrating to OAuth Server-to-Server Credentials
- Manage device authentication for Creative Cloud and Acrobat Pro
- Enterprise | Support and Expert Sessions
Set up identity with SSO
Configure Federated ID accounts to authenticate users through Single Sign-On integration with your identity provider.
Single Sign-On (SSO) allows your users to access Adobe products using the same credentials they use for other organizational applications. Rather than managing separate Adobe passwords, users authenticate through your organization's existing identity provider (IdP), streamlining access and strengthening security.
Setting up SSO for Adobe products requires configuring Federated ID accounts that link your enterprise directory to Adobe via federation. This integration gives your organization control over authentication while Adobe continues to host the identity records.
The role of Federated ID in SSO
Federated ID is the only identity type that supports SSO with Adobe products. Unlike Adobe ID (user-managed) or Enterprise ID (Adobe-authenticated), Federated ID routes all authentication requests through your organization's identity provider using the SAML 2.0 protocol.
This architecture is valuable for:
- Enterprise directory provisioning based on Active Directory or Azure AD
- Centralized control over authentication policies, including multi-factor authentication requirements
- Strict governance over app and service access
- Regulatory or security requirements that mandate organizational authentication management
When users with Federated IDs sign in to Adobe applications, they're redirected to your IdP, authenticate there, and are passed back to Adobe with a secure token confirming their identity.
SSO integration approaches
Adobe Admin Console supports three primary integration paths, each suited to different infrastructure environments.
Azure AD integration is the recommended approach for organizations that use Microsoft's cloud identity platform. The Azure AD connector simplifies configuration and automates user synchronization between Azure AD and the Admin Console, reducing ongoing administrative overhead.
SAML-based IdP integration provides flexibility for organizations that use identity providers other than Azure AD or Google. Any SAML 2.0–compliant IdP, including Okta, Ping Identity, Shibboleth, or AD FS, can federate with Adobe through this path. You configure the integration by exchanging SAML metadata between your IdP and the Admin Console.
Google Workspace integration mirrors the Azure AD approach for organizations standardized on Google's identity infrastructure. Like Azure AD, the Google connector supports both SSO setup and ongoing user synchronization.
Each integration requires you first to create a directory in the Admin Console (Settings > Identity > Directories), claim and verify your email domains, and then configure the connection to your IdP. The specific configuration steps vary by provider, but the conceptual model remains consistent: Adobe delegates authentication to your IdP while maintaining user and entitlement records in the Admin Console.
Post-setup identity infrastructure
Once SSO is operational, ongoing identity management centers on directories, domains, and directory trusts.
Directories serve as containers for SSO configuration and users. Each directory connects to a single IdP configuration, though you can create multiple directories if your organization uses multiple identity providers or needs to segment authentication policies by business unit.
Domains determine which users authenticate through which directory. When you link a domain—such as example.com—to a directory, any user with an email address at that domain is routed to that directory's IdP for authentication. Domain management also includes managing directory trusts when multiple Adobe organizations claim the same domain.
Changing identity providers requires coordination to avoid disrupting user access. The Admin Console supports migrating authentication providers by allowing you to configure a new directory, move domains, and transition users between directories. You can also move domains across directories or remove legacy directory users as your infrastructure evolves.
Understanding these management concepts helps you maintain stable authentication as organizational needs change, whether that means consolidating multiple IdPs, migrating from one vendor to another, or restructuring how business units map to directories.