-
Setup and onboarding
- Explore Adobe Admin Console
- Sign-in and access
-
Plan your deployment
- Basic concepts
- Deployment Guides
-
Deploy Creative Cloud for education
- Education Deployment Home
- Education Deployment K-12 Onboarding Wizard
- Education Deployment Simple Setup
- Education Deployment Setup With User Sync
- Education Deployment Setup with Roster Sync
- Education Deployment Key licensing Concepts
- Education Deployment Setup Concepts
- Education Deployment Quick Tips
- Approve Adobe apps in Google Admin Console
- Enable Adobe Express in Google Classroom
- Integrate Adobe Creative Cloud and Adobe Express with Canvas LMS
- Adobe Creative Cloud & Blackboard Learn
- Configuring SSO for District Portals and Learning Management Systems
- Roster syncing for license assignment with the Adobe Admin Console
- Kivuto FAQ
- Primary and Secondary Institution Eligibility Guidelines
-
Licensing
- Licensing overview
- Licensing types
-
Set up your organization
- Identity overview
- Set up identity and Single Sign-On
- Set up organization with Enterprise ID
- Setup Azure AD federation and sync
- Set up Google Federation and sync
- Configure Microsoft AD FS for use with Adobe SSO
- Configuring SSO for District Portals and Learning Management Systems
- Set up organization with other Identity providers
- SSO common questions and troubleshooting
- Set up Frame.io for enterprise
-
Identity and SSO
- Set up identity
- Integrate with Microsoft Entra
- Integrate with Google Sync
- Integrate with other SSO providers
- Troubleshoot
-
Manage your organization setup
- Manage existing directories and domains
- Enable automatic account creation
- Domain Enforcement for restricted authentication
- Set up organization via directory trust
- Migrate to a new authentication provider
- Asset settings
- Manage authentication settings
- Limit product access by IP addresses
- Privacy and security contacts
- Console settings
- Manage encryption
-
Directories, domains, and access
-
Directories and domains
- Create a directory for SAML identity providers
- Verify domain ownership
- Set up domains for directory authentication
- Move domains across directories
- Encrypted and trusted directory domain transfers
- Move directories between Admin Consoles
- Delete directories and domains
- Automatic account creation overview
- Enable automatic account creation
- Automatic federated account creation FAQ
- Domain enforcement
- Directory trusting
-
Directories and domains
-
Manage users
- Adobe Admin Console users
- Administrative roles
- Assign user roles for granular access control
- How to create custom roles
- Manage Frame.io account roles in Adobe Admin Console
- User management strategies
- Assign a license to teams user
- Team Management: Creative Cloud desktop app, Acrobat, Express
- Adobe's matching service
- Edit user identity type
- Manage user groups
- Manage directory users
- Exclude specific users from domain enforcement
- Manage developers
- Migrate existing users to the Adobe Admin Console
- Migrate Frame.io user management to the Adobe Admin Console
- Admin roles and hierarchy
- Enterprise admin permissions matrix
-
Settings
- Asset settings
- Manage encryption
-
Manage products and entitlements
-
Manage products and product profiles
- Manage products on Admin Console
- Add products and licenses
- Manage product profiles for enterprise users
- Manage automatic assignment rules
- Adobe Express Photos FAQs for administrators
- Assign users to Firefly custom models
- Enable Shared Credits for your organization
- Manage product requests
- Manage self-service policies
- Manage app integrations
- Manage product permissions in the Admin Console
- Single App | Creative Cloud for enterprise
- Manage Shared Device licenses
-
Manage products and product profiles
-
User management
- Understand user management
- Manage users and groups
- Manage admins
- Manage user roles
- Migrate users
-
Get started with Global Admin Console
- Adopt global administration
- Select an organization in the Global Admin Console
- Manage organization hierarchy
- Manage product profiles
- Manage administrators
- Manage user groups
- Create license assignment reports for multiple organizations
- Update organization policies
- Manage policy templates
- Allocate products to child organizations
- Execute pending jobs
- Download audit logs and export reports
- Export or import organization structure and product allocations
-
Products and entitlements
- Manage products
- Manage product profiles
- Special programs plans
- Manage entitlements
- Manage automatic assignment
- Manage product access
- Manage self-service policies
- Manage app integrations
- Frame.io integration
- Manage product permissions
-
Manage storage and assets
- Storage
- Manage projects
- Asset migration
- Reclaim assets from a user
- Student asset migration | EDU only
- Manage storage and assets
-
Manage services
- Manage services in the Admin Console
- Configure services
- Optional services
- Adobe Stock
- Enable Shared Credits for your organization
- Custom fonts
-
Adobe Asset Link
- Adobe Asset Link
- Adobe Asset Link Overview
- Create user group for Adobe Asset Link
- Configure Experience Manager Assets as a Cloud Service
- Deploy Adobe Asset Link
- Configure Adobe Experience Manager 6.x Assets for Adobe Asset Link
- Manage assets using Adobe Asset Link
- Adobe Asset Link for Adobe XD
- Troubleshoot Adobe Asset Link
- Known issues with Adobe Asset Link
- Adobe Acrobat Sign
-
Deploy apps and updates
- Overview
-
Create packages
- Packaging apps via the Admin Console
- Create Named User Licensing Packages
- Manage pre-generated packages
- Manage Packages
- Customize packages
- Deploy Packages
- Manage updates
- Adobe Update Server Setup Tool (AUSST)
- Adobe Remote Update Manager (RUM)
-
Deploy apps and updates
- Prepare for deployment
- Manage pre-generated packages
- Create packages
- Customize end-user experience
- Deploy packages
- Use third-party deployment tools
-
Manage Shared Device Licensing (SDL)
- Shared Device Licensing overview
- Deploy Shared Device Licensing
- Manage SDL profiles and user access
- Activate shared device licenses
- Use the Shared Device Licensing toolkit
- Recover shared device licenses
- Shared Device Licensing identity FAQ
- Shared Device Licensing deployment FAQ
- Shared Device Licensing access FAQ
- Known issues in Shared Device Licensing
- Adobe Update Server Setup Tool (AUSST)
- Adobe Remote Update Manager (RUM)
- Troubleshoot
-
Manage your Teams account
- Manage your account
- Complimentary membership for team members
- Update payment details on your Teams account
- Download and email invoices
- Change the contract owner of your Teams account
- Change your Creative Cloud for teams plan
- Change reseller
- Cancel Creative Cloud for teams licenses
- Purchase Authorization Compliance
- Contracts and renewals
- Renewals
- Reports and logs
-
Manage contracts
- Automated expiration stages for ETLA contracts
- Switching contract types within an existing Adobe Admin Console
- Manage trials and special offers
- Complimentary membership for team members
- Creative Cloud for enterprise - free membership
- Frame.io and Creative Cloud for teams and enterprise plans
- Value Incentive Plan (VIP) in China
- VIP Select Help
-
Get started with Global Admin Console
- Get started
- Manage your organization
- Reports audit
-
Get help
- Enterprise and teams | Contact Adobe Customer Care
- Support options
- Teams | Support and Expert Sessions
-
General troubleshooting
- Microsoft Purview Information Protection support in Acrobat
- Use the Creative Cloud Cleaner tool to fix installation issues
- Fix app launch errors on Shared Device Licensing machines
- Technical support boundaries for virtualized or server-based environments
- Resolve trial and license expired errors
- Migrating to OAuth Server-to-Server Credentials
- Manage device authentication for Creative Cloud and Acrobat Pro
- Enterprise | Support and Expert Sessions
Shared Device Licensing overview
Learn how device-based licensing works for lab and classroom deployments where multiple users share computers.
If you manage labs or classrooms where students rotate through shared workstations, you need a licensing model that ties software to machines rather than individuals. Shared Device Licensing addresses this challenge by assigning Creative Cloud apps to devices rather than to user accounts. Anyone who accesses the machines can launch the installed apps.
What is Shared Device Licensing
Shared Device Licensing is device-based licensing for shared computers. Rather than associating licenses with individual users, Shared Device Licensing ties them to the machine. Users see a sign-in prompt when they launch an app. A banner indicates the machine uses shared device licensing and reminds users to sign out when finished and to avoid storing files locally.
Shared Device Licensing isn't designed for use on machines used by dedicated users. For dedicated users, we recommend you deploy named-user licenses.
Shared Device Licensing versus Named User Licensing
Named User Licensing ties the license to a user's identity. When the user signs in, they can activate Adobe apps on any computer they have access to. The license travels with the user across devices and provides full access to cloud services like Adobe Fonts, cloud storage, and Creative Cloud Libraries.
Shared Device Licensing ties the license to a specific computer. Apps activate only on machines where you've installed the license package, regardless of who signs in. Users must still authenticate with valid credentials to launch apps, but the license itself resides on the device. This means a single shared device license supports unlimited users on a particular machine.
Here are the key differences between the two licensing types:
- License location: Named licenses follow the user, shared device licenses stay with the machine
- Service access: Named licenses include cloud storage and libraries by default. Shared device licenses don’t provide these entitlements, but users with individual service access can still use them.
- Deployment scope: Named licenses activate on any device the user accesses. However, shared device licenses work only on specifically configured machines
You can read more about the Adobe licensing methods if you're deciding between the two models.
End user experience
When a user launches an app on a shared device, they see a prompt to sign in with their Adobe credentials. The app displays a banner indicating the machine is configured for shared device licensing. It reminds users to sign out when finished and not to store files locally on the shared computer.
The credentials users need depend on how you've set up identity for your organization: Enterprise ID, Federated ID, or Adobe ID, depending on your access policies. Successful sign-in grants access to the installed applications.
If the user's account includes additional entitlements, such as Adobe Fonts or cloud storage, the services remain available during the session.
Controlling access to shared devices
Use the Admin Console to restrict who can use apps on shared devices and where devices can operate. Layer these controls to match your security needs.
Identity types
You configure identity requirements through product profiles in the Admin Console. Your choices determine what kind of accounts can access the apps:
- Enterprise ID or Federated ID: Organization-owned identities you manage directly. K-12 schools must use these identity types. They provide complete control over account creation, lifecycle, and data ownership.
- Adobe ID: Personal accounts owned by individual users. Higher education institutions may allow Adobe IDs for open-access scenarios, though the individual or organization may legally own the data depending on the account configuration.
Learn more about the identity types supported on the Admin Console.
Access policies
Access policies define which types of users can launch apps on your shared devices:
- Open Access: Anyone with a valid Adobe account can sign in and use the apps, including users with personal Adobe IDs who aren't part of your organization. Use it for public computer labs where visitors, students, and staff all need access.
- Organization users only: Limits access to accounts you've added to your Admin Console, regardless of identity type. It prevents unauthorized external users from accessing apps while still supporting any identity configuration you've implemented.
- Enterprise/Federated users only: Restricts access exclusively to Enterprise ID and Federated ID accounts. Personal Adobe IDs cannot launch apps even if the user is affiliated with your organization. Use it for K-12 environments to ensure only verified students access the software.
Egress IP address restrictions
Egress IP controls prevent shared device apps from activating when devices connect from outside your approved networks. You specify public IP address ranges that your lab networks use when connecting to the internet. If someone moves a portable shared device to a different network, the apps won't activate even though the license is installed.
This control applies to lab machines and laptops. Update IP ranges in the Admin Console when your provider changes them if you don't use static IPs.
Machine associations
Organize shared devices into product profiles based on infrastructure attributes to simplify management across many devices:
- Microsoft Active Directory organizational units: Machines belonging to specific OUs automatically associate with designated product profiles. If your IT structure organizes computers by department, you can create product profiles that mirror those divisions.
- LAN IP address ranges: Machines with addresses in specified local network ranges associate with product profiles. Use it when your labs or library computers occupy defined network segments.
- Installed packages: Machines with specific license packages installed automatically belong to the corresponding product profiles. Use this approach when building different packages for different computer types or locations.
When a machine matches multiple product profiles, the Admin Console applies them in order of priority. Organizational unit takes precedence, then LAN IP range, then package assignment.
Once you've decided on your identity approach and access policies, see Deploy Shared Device Licensing for the full setup process, including creating deployment packages, assigning product profiles, and distributing packages to shared devices.
Migrating to Shared Device Licensing
Organizations can transition from older licensing models to Shared Device Licensing:
From Device Licensing: Adobe provided complimentary upgrades from the legacy Device Licensing program to Shared Device Licensing. The older Device Licensing program doesn't provide access to the latest version of Creative Cloud apps. After migration, previously licensed apps continue working for 30 days while you create and deploy new shared device license packages.
From Serial Number Licensing: You can deploy shared device license packages alongside serial number packages. Both licensing methods coexist on the same machine. Continue using serial-number–licensed apps until their licenses expire. Alternatively, uninstall them and deploy only shared device packages for newer app versions.
Migration to Shared Device Licensing is permanent and cannot be reversed.