To set up automatic assignment rules, sign in to the Adobe Admin Console and navigate to Products > Automatic assignment rules.
Understand how auto - provisioning rules streamline product assignment for eligible users.
Automatic assignment rules enable System Administrators to automatically provision products to eligible users based on predefined criteria. Administrators can apply rules to all users or restrict eligibility to selected directories and domains. This selected set of users gains immediate access to a product when they request it from an entry point indicated by the administrator.
Users can request access from an Adobe desktop application or from the following surfaces:
- Creative Cloud desktop app
- Creative Cloud on the web (desktop only)
- Adobe Stock
- Adobe Acrobat Sign
- Adobe Express
- Adobe Firefly
- Developer Console
- Adobe Acrobat (AI Assistant only)
Automatic assignment rules are available only to organizations using Adobe storage for business, which is being rolled out globally in phases.
Alternatively, you can manually review each product request that the users send instead of setting up assignment rules. Learn more about the end-user request access experience.
License availability and contract behavior
When all available licenses for a product are assigned, the Administrators receive an Admin Console warning and email notification to Buy More licenses. The requesting user is notified by email that no more licenses are available. After more licenses are added, users must request access again.
For VIP contracts with enterprise products, administrators and requesting users are notified when licenses are unavailable. As more licenses become available, pending users receive access automatically in request order and are notified by email. To view pending users, go to Admin Console > Products, choose a product, and select NO ACCESS. In the Users tab, administrators can check for users who no longer need access to the product and remove them to free up licenses.
For enterprise contracts that allow over-delegation, the eligible users receive automatic approval regardless of the remaining license count. The licenses can be over-assigned beyond the selected quantity.
This over-assigned feature is only available if your organization uses Adobe storage for business, which is being rolled out globally in a phased manner.
Set-up automatic assignment rules
Select Add product.
Select a product and product profile (enterprise only) to be automatically assigned to eligible users.
- You can create more than one rule per product, but each must include a unique product profile.
- If you create multiple rules for the same product using different product profiles, multiple licenses may be assigned to eligible users when they request access.
- When you create an auto-assignment rule for a product that provides API access, it automatically assigns the users as developers (if they aren’t already assigned) to provide them with access to APIs in Adobe developer tools. Learn more about managing API developers.
Select Next and choose eligible users for the role:
Select from the following options:
- All users in this organization: All existing and new users added to the organization are eligible to be automatically provisioned a license upon request for the selected product.
- Users in selected directories or domains: All existing and new users added to the selected directories or domains are eligible to be automatically provisioned a license upon request for the selected product.
The option All users in this organization becomes the default option if the product selected in the previous step is a Teams product.
If you choose Users in selected directories or domains, select Add directory.
When you select a directory, all active domains claimed in the directory are included. To select specific domains, deselect the checkbox and select the required domains.
Select Next and specify the request access method for your users.
- On-demand access:
- Allows eligible users to request access to a product from within an integrated Adobe application.
- Generates a product access URL that can be shared with eligible users as an additional access point.
- URL-only access:
- Allows eligible users to request access only via a link provided by an administrator. This link can be shared via email, an internal site, or any other channel directly with the users.
Adobe recommends using URL-only Access in the following cases:
If you want to extend the option of automatic access to a subset of users.
If you want to share the option to request access, but hide it from the integrated Adobe app surfaces.
If the product associated with the rule doesn't support in-app requests and isn’t available in the Creative Cloud desktop app or Creative Cloud on the web (like Adobe Acrobat Sign and Adobe Analytics). Here is a list of apps from which users can request access.
Select Save.
Upon requesting access, eligible users are automatically granted a license based on the settings chosen by the administrator. For on-demand access, if more than one rule applies to the requested product, the user is assigned all product profiles associated with rules for which they are eligible.
For enterprise products, administrators select a product and a product profile. If multiple rules for the same product use different profiles, eligible users receive licenses for all applicable product profiles when they request access. Teams products don’t require product profile selection.
When a rule assigns a product that provides API access, the system automatically assigns the developer role if the user doesn’t already have it.