Configure sharing restrictions and authorized domains

Last updated on Aug 3, 2026

Apply organization-wide policies that control how users share Creative Cloud and Document Cloud assets with external collaborators.

Select a sharing restrictions policy

In the Adobe Admin Console, select Settings > Asset Settings.

In the Sharing Restrictions Policy section, choose a policy based on your security requirements.

If you select Sharing Limited to Org Members and Trusted Users, first define your authorized domains.

Note

To use the option Sharing Limited to Org Members and Trusted Users with Document Cloud, you must add your claimed and trusted domains to the Authorized Domains.

Select Confirm to apply the policy.

Sharing policy options

Sharing Options

Restrictions

Impact on existing links and collaborations

No restrictions (Default)

Users can share public links, publish posts to social media, and collaborate on shared folders with anyone inside or outside the organization. Works best for enterprises where employees have access to every Creative Cloud and Document Cloud feature.

No impact.

No public link sharing

Prevents users from creating public links and posting to social media but allows invitation-based sharing.

Deletes all existing public links. Users can no longer access Content Schedules in Adobe Express, and scheduled social media posts are paused.

Sharing is limited to org members and trusted users.

Restricts invitation-based sharing to recipients in your org, claimed domains, trusted domains, and authorized domains. After you set this policy, users can only share organization-owned assets with org members or users in allowed domains.

Deletes all existing public links and all collaborations on shared documents and folders with users who are not in the org or in an allowed domain. Users can no longer access Content Schedules in Adobe Express, and scheduled social media posts are paused.

To share organization assets externally, add the agency’s domain to the authorized list or provide the individual with an Enterprise ID or Federated ID. Alternatively, add the user as a Business ID to your organization on the Admin Console.

Configure access request policy

In the Adobe Admin Console, select Settings > Asset Settings.

In the Access Request Policy section, select your preferred option.

Select Confirm to apply the policy.

Access request policy options

By default, access requests are allowed. A user with the link to a shared resource but without permission to view it can request access. Users with sharing permissions on the document receive notifications for each access request and can decide whether to grant or deny access. The requester receives a notification when access is granted or denied.

Choose No access requests for added privacy to prevent users from requesting access to documents that have not been shared with them.

Note

If you have a Sharing limited to org members and trusted users policy selected, that restriction applies when users attempt to grant access to an access request from someone outside the organization.

Implications for users in multiple organizations

Adobe strongly recommends that a user only be a member of one organization. Where users must be members of multiple organizations, all organizations must have the same Sharing Policy and Allow Lists configured.

Move assets policy

On the Asset settings page in the Admin Console, you can configure the Move assets policy to control whether users in your organization can move assets outside the organization's storage.

Option

Description

Allow asset move (Default)

Users in your organization can move assets to locations outside the organization’s storage, such as shared projects or folders.

Restrict asset move

Users in your organization can't move assets to locations outside the organization’s storage. Copying assets isn't affected by this policy.

Changes to the Move assets policy setting are captured in the audit log. Asset move events across organizations are captured in the content log.

Note

Regardless of the policy setting, admins can move assets outside the organization’s storage, while users outside the organization cannot.

Add authorized domains

Authorized domains are external domains that are safe to collaborate with. If you have selected Sharing Limited to Org Members and Trusted Users, users can share assets with recipients in these domains.

In the Adobe Admin Console, select Settings > Asset Settings > Authorized domains.

Select Add Domains.

In the Add Domains dialog, enter the domains. You can add multiple domains separated by commas.

Select Add to save the domains to your authorized list.

Remove authorized domains

In the Adobe Admin Console, select Settings > Asset Settings > Authorized domains.

Select the checkbox for each domain name you want to remove.

Select Remove Domains.

Select Remove in the confirmation dialog to remove the domains.

If the sharing option is set to Sharing Limited to Org Members and Trusted Users, any shares to the removed domain are immediately revoked.

Caution

Removing a domain from the authorized list deletes all existing collaborations on shared documents and folders between users in that domain and users in your organization. Implications for users in multiple organizations