Set up proxy support for Creative Cloud apps

Last updated on Sep 8, 2026

Learn about proxy configurations and authentication types supported by Creative Cloud applications and services.

Note

This article applies to Adobe Creative Cloud 2019 and later.

Adobe Creative Cloud provides access to various Internet-based services, including Assets, Fonts, and Behance. Adobe Creative Cloud also includes Internet-first apps, such as Adobe XD and Adobe Dimension. In many organizations, a proxy server is implemented to restrict and control access to the Internet. This article describes the various levels of support for proxy environments in Creative Cloud applications and services.

Note

Some proxy servers allow system admins to safelist domains. If you are a system admin in your organization, use this document to allowlist the appropriate domains. Your end users will, then, not be prompted to enter their proxy server credentials when they open any Creative Cloud application.

Proxy authentication for desktop apps

When end users open a Creative Cloud application, they are prompted to enter their proxy credentials:

macOS users: If you are a macOS user, you are prompted with the following dialog if you have not entered your proxy credentials in System Preferences:

Enter your proxy credentials in System Preferences on your computer, then select Try Again.

Enter your proxy credentials.

Note

For Windows users, this dialog is displayed when you launch the Creative Cloud application.

Check Remember proxy credentials, then select OK.

Proxy authentication for Creative Cloud desktop app

When the Creative Cloud Desktop app is first launched and detects a proxy, it prompts for credentials.

Enter the proxy server credentials and check Remember me.

Offline experience

If you are offline, you are prompted with the following message:

If you are already connected to the Internet, see the connectivity troubleshooting guide for more details.

Proxy requirements for Creative Cloud Libraries

In an enterprise environment, Creative Cloud Libraries must connect to localhost for the Libraries panel in applications to sync correctly. Therefore, if you're using Libraries, set localhost and 127.0.0.1 to bypass the proxy server for the enterprise environment. On a macOS computer, if you're using Proxy Auto-configuration (PAC) or the Web Proxy Autodiscovery Protocol (WPAD), you also need to enable the Exclude simple hostnames setting.

Note

This setting is required if you manually enter the proxy server URL or IP. For more information on Creative Cloud Libraries-specific proxy configuration details, see Configure your proxy to work with Libraries and Configuration of proxy by a network administrator.

Supported proxy setting types

The following proxy configurations are supported on Mac and Windows:

  • Proxy settings using PAC URL, either with or without authentication
  • Auto Proxy Discovery (WPAD)
  • Basic authentication. If a user provides credentials in the Creative Cloud app, then Creative Cloud Libraries use the credentials. If the user does not provide credentials in the Creative Cloud app, the Creative Cloud Libraries panel prompts them to do so.
  • Kerberos authentication is supported for Creative Cloud libraries and the Creative Cloud desktop app. However, Kerberos authentication is not supported for Creative Cloud 2015 products.

Unsupported proxy setting types

The following proxy configurations are not supported:

  • NTLM authentication
  • Local PAC file support

It is possible to apply the following workaround: allowlisting. The following list of domains can be allowlisted on a proxy server so they do not require authentication. In this case, a proxy server that requires NTLM or Kerberos authentication should still allow the connection from Creative Cloud Desktop and other Adobe applications that do not support these protocols. Alternatively, these domains can be allowed on the firewall to enable a direct connection if the proxy configuration is set for Adobe applications. This case is apparent from a network trace (for example, with Wireshark, Fiddler, Charles Proxy or by examining the firewall logs).*.adobe.com *.adobelogin.com *.adobeexchange.com *.adobesc.com *.macromedia.com *.typekit.com *.behance.net *.typekit.net *.okta.com *.adobe. There could be other domains that Adobe applications use. Still, the ones listed above should be sufficient for logging in and licensing Adobe software.- Manually changing PAC configuration. In some cases, a customer may be able to change their network configuration. Because WPAD is not currently supported and the format of these configuration files matches that of PAC configurations, the URL of the WPAD script can be pasted into the field labelled "automatic configuration script." Proxy Information to gather

  1. Collect screenshots for all proxy issue support cases and attach them to the support cases within Hendrix.
  2. Apply the tag "CCE Proxy Issue" to the case in Hendrix by clicking "Tag(s): Edit" under the customer contact information, then "CCE" and selecting "CCE proxy issue", then clicking "Apply".
  3. Capture the following information for each proxy case:
  • Proxy server software and version number: (for example, Squid 3.1.20 on Debian Linux release wheezy, Websense proxy 8.0.1, and so on).
  • Proxy authentication type and fallback details: (for example, Kerberos with basic authentication as a fallback) PAC configuration location: (local file://c:\proxy.pac or remote http://intranet/proxy.pac )
  • Has the local machine been added as an exception to the proxy configuration to allow Edge Reflow or Creative Cloud Libraries, which run as local services, to connect to the workstation itself, yes or no?
  • Version of CCP (for example, 1.9.1.0)
  • Version of CCDA (for example, Thor 2.2.0.129)
  • If possible, obtain clear and simple logs from either Charles Proxy or Wireshark with no other applications running on the system, which were taken during the problem occurring, with the time of the problem noted in the case.
  • Use the Adobe log collector to obtain logs when the problem is observed, annotating where necessary for changes to the configuration made during diagnostics (for example, "logs showing failure to connect when using PAC configuration")
  • Description of symptoms and steps required to reproduce the problem

Support for pac files

  • The Creative Cloud desktop application and Creative Cloud Packager support remote PAC files with basic authentication (PAC files stored on a remote server and referenced by URL).
  • The Creative Cloud desktop application and Creative Cloud Packager do not support locally stored pac files.
  • NTLM authentication is not supported.