User Guide Cancel

Add Microsoft Azure Sync to your directory

  1. Adobe Enterprise & Teams: Panduan administrasi
  2. Rencanakan penerapan Anda
    1. Konsep dasar
      1. Pemberian lisensi
      2. Identitas
      3. Manajemen pengguna
      4. Penerapan aplikasi
      5. Ikhtisar Admin Console
      6. Peran admin
    2. Panduan Penerapan
      1. Panduan penerapan Pengguna Bernama
      2. Panduan Penerapan SDL
      3. Terapkan Adobe Acrobat 
    3. Terapkan Creative Cloud for Education
      1. Beranda penerapan
      2. Wizard Orientasi K-12
      3. Penyiapan sederhana
      4. Menyinkronkan Pengguna
      5. Roster Sync K-12 (AS)
      6. Konsep pemberian lisensi utama
      7. Opsi penerapan
      8. Kiat ringkas
      9. Setujui aplikasi Adobe di Admin Console Google
      10. Aktifkan Adobe Express di Google Classroom
      11. Integrasi dengan Canvas LMS
      12. Integrasi dengan Blackboard Learn
      13. Mengonfigurasi SSO untuk Portal Distrik dan LMS
      14. Tambahkan pengguna melalui Roster Sync
      15. FAQ Kivuto
      16. Pedoman kelayakan institusi Primer dan Sekunder
  3. Atur organisasi Anda
    1. Tipe identitas | Ringkasan
    2. Atur identitas | Ringkasan
    3. Atur organisasi dengan Enterprise ID
    4. Atur federasi dan sinkronisasi Azure AD
      1. Atur SSO dengan Microsoft melalui Azure OIDC
      2. Tambahkan Azure Sync ke direktori Anda
      3. Sinkronisasi peran untuk Pendidikan
      4. FAQ Azure Connector
    5. Atur Google Federation dan sinkronkan
      1. Atur SSO dengan Google Federation
      2. Tambahkan Google Sync ke direktori Anda
      3. FAQ Google federation
    6. Atur organisasi dengan Microsoft ADFS
    7. Mengatur organisasi untuk Portal Distrik dan LMS
    8. Atur organisasi dengan Penyedia Identitas lainnya
      1. Buat direktori
      2. Verifikasi kepemilikan domain
      3. Tambahkan domain ke direktori
    9. Pertanyaan umum dan pemecahan masalah SSO
      1. Pertanyaan Umum SSO
      2. Pemecahan Masalah SSO
      3. Pertanyaan umum tentang pendidikan
  4. Kelola pengaturan organisasi Anda
    1. Kelola domain dan direktori yang ada
    2. Aktifkan pembuatan akun otomatis
    3. Atur organisasi melalui kepercayaan direktori
    4. Bermigrasi ke penyedia autentikasi baru 
    5. Pengaturan aset
    6. Pengaturan autentikasi
    7. Kontak privasi dan keamanan
    8. Pengaturan Console
    9. Mengelola enkripsi  
  5. Mengelola pengguna
    1. Ikhtisar
    2. Peran administratif
    3. Strategi manajemen pengguna
      1. Mengelola pengguna secara individu   
      2. Mengelola banyak pengguna (CSV Massal)
      3. User Sync Tool (UST)
      4. Microsoft Azure Sync
      5. Google Federation Sync
    4. Tetapkan lisensi ke pengguna Tim
    5. Manajemen pengguna dalam aplikasi untuk tim
      1. Mengelola tim Anda di Adobe Express
      2. Mengelola tim Anda di Adobe Acrobat
    6. Tambahkan pengguna dengan domain email yang cocok
    7. Mengubah jenis identitas pengguna
    8. Mengelola grup pengguna
    9. Mengelola pengguna direktori
    10. Mengelola pengembang
    11. Memigrasikan pengguna yang ada ke Adobe Admin Console
    12. Memigrasikan manajemen pengguna ke Adobe Admin Console
  6. Mengelola produk dan hak
    1. Mengelola produk dan profil produk
      1. Mengelola produk
      2. Beli produk dan lisensi
      3. Mengelola profil produk untuk pengguna perusahaan
      4. Mengelola aturan penugasan otomatis
      5. Beri hak kepada pengguna untuk melatih model kustom Firefly
      6. Meninjau permintaan produk
      7. Mengelola kebijakan layanan mandiri
      8. Mengelola integrasi aplikasi
      9. Mengelola izin produk di Admin Console  
      10. Mengaktifkan/menonaktifkan layanan untuk profil produk
      11. Aplikasi Tunggal | Creative Cloud untuk perusahaan
      12. Layanan opsional
    2. Mengelola lisensi Perangkat Bersama
      1. Yang baru
      2. Panduan penerapan
      3. Buat paket
      4. Pulihkan lisensi
      5. Kelola profil
      6. Toolkit pemberian lisensi
      7. FAQ Pemberian Lisensi Perangkat Bersama
  7. Mulai menggunakan Global Admin Console
    1. Mengadopsi administrasi global
    2. Memilih organisasi Anda
    3. Mengelola hierarki organisasi
    4. Mengelola profil produk
    5. Mengelola administrator
    6. Mengelola grup pengguna
    7. Memperbarui kebijakan organisasi
    8. Mengelola templat kebijakan
    9. Mengalokasikan produk ke organisasi turunan
    10. Menjalankan pekerjaan yang tertunda
    11. Menjelajahi wawasan
    12. Mengekspor atau mengimpor struktur organisasi
  8. Kelola penyimpanan dan aset
    1. Penyimpanan
      1. Kelola penyimpanan perusahaan
      2. Adobe Creative Cloud: Pembaruan pada penyimpanan
      3. Kelola penyimpanan Adobe
    2. Migrasi aset
      1. Migrasi Aset Otomatis
      2. FAQ Migrasi Aset Otomatis  
      3. Kelola aset yang ditransfer
    3. Klaim kembali aset dari pengguna
    4. Migrasi aset siswa | hanya untuk EDU
      1. Migrasi aset siswa otomatis
      2. Migrasikan aset Anda
  9. Kelola layanan
    1. Adobe Stock
      1. Paket kredit Adobe Stock untuk tim
      2. Adobe Stock untuk perusahaan
      3. Gunakan Adobe Stock untuk perusahaan
      4. Persetujuan Lisensi Adobe Stock
    2. Font khusus
    3. Adobe Asset Link
      1. Ikhtisar
      2. Buat grup pengguna
      3. Konfigurasikan Adobe Experience Manager Assets
      4. Konfigurasikan dan instal Adobe Asset Link
      5. Kelola aset
      6. Adobe Asset Link untuk XD
    4. Adobe Acrobat Sign
      1. Atur Adobe Acrobat Sign untuk perusahaan atau tim
      2. Adobe Acrobat Sign - Administrator fitur tim
      3. Kelola Adobe Acrobat Sign di Admin Console
    5. Creative Cloud untuk perusahaan - keanggotaan gratis
      1. Ikhtisar
  10. Terapkan aplikasi dan pembaruan
    1. Ikhtisar
      1. Menerapkan dan mengirimkan aplikasi dan pembaruan
      2. Paket untuk diterapkan
      3. Siapkan untuk menerapkan
    2. Buat paket
      1. Aplikasi paket melalui Admin Console
      2. Buat Paket Pemberian Lisensi Pengguna Bernama
      3. Templat Adobe untuk paket
      4. Kelola paket
      5. Kelola lisensi perangkat
      6. Pemberian lisensi nomor seri
    3. Sesuaikan paket
      1. Sesuaikan Aplikasi desktop Creative Cloud
      2. Sertakan ekstensi dalam paket Anda
    4. Terapkan Paket 
      1. Terapkan paket
      2. Terapkan paket Adobe menggunakan Microsoft Intune
      3. Terapkan paket Adobe dengan SCCM
      4. Terapkan paket Adobe dengan ARD
      5. Instal produk di folder Pengecualian
      6. Hapus instalan produk Creative Cloud
      7. Gunakan edisi perusahaan toolkit penyediaan Adobe
      8. Pengidentifikasi pemberian lisensi Adobe Creative Cloud
    5. Kelola pembaruan
      1. Ubah manajemen untuk pelanggan perusahaan dan tim Adobe
      2. Terapkan pembaruan
    6. Adobe Update Server Setup Tool (AUSST)
      1. Ikhtisar AUSST
      2. Atur server pembaruan internal
      3. Pertahankan server pembaruan internal
      4. Kasus penggunaan umum AUSST   
      5. Pecahkan masalah server pembaruan internal
    7. Adobe Remote Update Manager (RUM)
      1. Catatan rilis
      2. Gunakan Adobe Remote Update Manager
    8. Memecahkan masalah
      1. Memecahkan masalah kesalahan penginstalan dan penghapusan instalan aplikasi Creative Cloud
      2. Kueri mesin klien untuk memeriksa apakah suatu paket diterapkan
      3. Pesan kesalahan "Penginstalan Gagal" paket Creative Cloud
  11. Kelola akun Teams Anda
    1. Ikhtisar
    2. Memperbarui detail pembayaran
    3. Kelola faktur
    4. Ubah pemilik kontrak
    5. Ubah paket Anda
    6. Ubah pengecer
    7. Batalkan paket Anda
    8. Kepatuhan Permintaan Pembelian
  12. Perpanjangan
    1. Keanggotaan Teams: Perpanjangan
    2. Perusahaan di VIP: Perpanjangan dan kepatuhan
  13. Kelola kontrak
    1. Tahapan kedaluwarsa otomatis untuk kontrak ETLA
    2. Mengalihkan jenis kontrak dalam Adobe Admin Console yang ada
    3. Paket Insentif Nilai (VIP) di Tiongkok
    4. Bantuan Pemilihan VIP
  14. Laporan & log
    1. Log Audit
    2. Laporan tugas
    3. Log Konten
  15. Dapatkan bantuan
    1. Hubungi Layanan Pelanggan Adobe
    2. Opsi dukungan untuk akun tim
    3. Opsi dukungan untuk akun perusahaan
    4. Opsi dukungan untuk Experience Cloud

Azure Sync automates the user management for your Admin Console directory. You can easily add Azure Sync to any federated directory in the Admin Console regardless of its identity provider (IdP). To use Azure Sync, you must have your organization's users and groups data stored in the Microsoft Azure Active Directory (Azure AD).

Note:
  • If your identity provider is Microsoft Azure Active Directory (Azure AD) and you do not have a federated directory in the Adobe Admin Console; you can set up federation using the following ways:
    • OpenID Connect (OIDC): Create a federated directory in seconds via OIDC. The process to set up lies mostly within the Adobe Admin Console.
    • SSO with Azure AD via SAML: Create a federated directory using Azure AD with SAML setup. The process to set up lies mostly within the Microsoft Azure Portal.
  • If you have a functioning SAML-based directory, you can add sync capability on top of your existing setup.
  • You cannot manage users manually or by using other user sync methods if you've set up Azure sync for a directory. See notes prior to sync and common questions to learn more.

Overview

You can add Azure Sync to any directory in the Adobe Admin Console to automate its user management process. Azure Sync uses SCIM-protocol for user management and offers you control over user and group being sent to Adobe. Azure AD users synchronized with the Adobe Admin Console are unique and can be assigned to one or more product profiles.

After you've set up Azure Sync, Azure AD starts to send data to the Adobe Admin Console as per the Azure AD directory's user and group provisioning. All the details associated with the directory are displayed in the Settings section of the Adobe Admin Console.

Benefits of Azure Sync

The key advantages of the Azure Sync with your directory in the Adobe Admin Console are:

 Manage everything in Azure AD

 Control what data is sent to Adobe

 No need for another service or API setup

 Customize Azure AD user attribute mapping

 Add sync to previously configured directories

 Add Azure sync to directories set up for any IdP

 Onboard and offboard users easily using Azure AD

Prerequisites

To integrate Adobe Admin Console User management with Azure AD, you need the following:

  • Microsoft Azure AD account with user- and group-data
  • Adobe products that belong to any of the following: Creative Cloud for enterprise, Document Cloud for enterprise, or Experience Cloud 
  • A federated directory in the Adobe Admin Console with verified domains

Supported integration scenarios

Directory setup may differ and Azure Sync supports varying scenarios, which requires extra steps to set up Azure Sync. Use the table to follow steps based on your directory setup:

Directory setup scenario

Method to add sync

Single federated directory with one or more domains in the same Azure AD tenant. 

Follow Add Sync steps to establish Azure Sync. 

Multiple federated directories with one or more domains that belong to the same Azure AD tenant. 

  1. Consolidate domains into a single federated directory. 
  2. Follow Add Sync steps to establish Azure Sync. 

 

Multiple federated directories with one or more domains that belong to different Azure AD tenants.  

  1. Follow Add Sync steps to establish Azure Sync for a single directory.
  2. Repeat Azure Sync setup for all separate directories that require sync. 

 

Notes prior to sync configuration

Follow the points below to see the best practices and Adobe Recommendations before you set up Azure Sync:

  • Export the list of existing users before adding Azure Sync to keep a record of all user accounts and provisioned licenses when you set up.
  • If you've set up Azure AD SSO with Open ID Connect (OIDC), you must add a new Adobe Identity Management application in Microsoft Azure Portal to set up directory sync.
  • If you've set up Azure AD SSO with SAML, use the existing Adobe Identity Management application to configure directory sync. Follow the steps mentioned in the Microsoft document to configure automatic user provisioning with the Adobe Identity Management application.
  • Azure Sync decouples email from username, allowing users to use a differing email and username value to validate sign-in and access Adobe products and services, collaborate in projects, share files, etc.​ Follow the steps in the Microsoft document to customize the user provisioning attribute mapping.
  • If you are integrating Azure Sync to a directory having Federated ID users, verify that their username field format matches the user principal name (UPN) in Azure AD before you run the initial sync.
    If these values do not match, the Admin Console perceives this as a net-new user account and creates duplicate records for a single user. You can update the attribute mapping to ensure that the values passed by sync match the values in the user profiles in the Admin Console, which will automatically update their accounts upon the next sync.
  • Azure Sync can be established only in an Admin Console with at least one federated directory and domain set up. If the Admin Console with Azure Sync (owning Console) is in a trust relationship with other Admin Consoles (trustee Consoles), the trustees must use another form of user management, such as User Sync Tool, User Management API, or bulk CSV upload, to create, manage, and license Federated ID users.
    To add users to a trustee Console for license provisioning, you must first add the user to the owning Console.
  • If your organization uses the User Sync Tool or a UMAPI integration, you must first pause the integration. Then, add Azure Sync to automate user management from Azure AD. Once Azure Sync is configured and running, you can completely remove the User Sync Tool or UMAPI integration.
  • Your organization must have a Premium (P1 or P2) or Microsoft 365 (E3 or A3) subscription with Azure AD to use group-based assignment capabilities. It allows you to choose specific groups and users to be synced to the Adobe Admin Console.
    Organizations without these subscription levels can only sync all the users and groups to the Adobe Admin Console at once. The system will sync all users and groups automatically and generate an Adobe Federated ID for the synced users. Read more about Azure AD subscription plans and options for updating.
  • To move a domain to or from a directory established with Azure Sync, you must first enable editing for the directory temporarily. Once enabled, move the desired domain to or from the Azure AD-synced directory before disabling edit capabilities for the directory.
  • Azure sync does not sync users from groups with the HiddenMembership attribute in the Azure AD. To sync specific users, create a group on Azure AD and copy the respective users to the new group.

Add Azure Sync to a federated directory

You can add Azure Sync to an Adobe Admin Console federated directory with the required domains linked to it. To add sync to an established federated directory, follow the process below:

  1. On the Settings tab of the Adobe Admin Console, navigate to Directory Details > Sync. Click Add Sync.

  2. Select Sync users from Microsoft Azure card and click Next.

  3. Steps in Microsoft Azure Portal:

    Leave the Admin Console window open for reference, and open Microsoft Azure Portal in a separate browser. Then, follow the steps mentioned in the Microsoft doc to configure automatic user provisioning.

    Note:
    • You can sync nested groups from Azure AD through the Azure Sync integration, though nested groups are not automatically synced when the parent node of the group is added to the sync scope. You should also add Nested groups to the scope to include them in the automated sync.

    • Organizations must have a Premium (P1 or P2) or Microsoft 365 (E3 or A3) subscription with Azure Active Directory to use group-based assignment capabilities which allows an administrator to choose specific groups and users as the only objects to be synced to the Adobe Admin Console.

      Organizations without these subscription levels can only sync individual users (not groups) or all users and groups in the Azure AD to the Adobe Admin Console. Check your Microsoft Azure subscription to confirm your organization's level and get in touch with your Microsoft representative if required.

    After set up, Azure starts to process and send data for provisioning in Adobe. You can review other instruction via Microsoft Application Management tutorials.

  4. In the Adobe Admin Console window, check the box to confirm the Authorization of Adobe access and completed setup in Azure AD. Then choose Done.

  5. Go back to directory details > SyncSync Source is displayed.

    Azure Sync is integrated with your directory but it hasn't yet started. To initiate sync, you have to click Go to Settings and edit sync settings.

Edit Sync settings

A System Administrator can update settings for the Sync Source once the setup is complete by choosing Go to Settings from the Directory settings > Sync tab. Setting options include:

  • Allow editing synced data in Admin Console: Once Azure Sync is established, all users and sync-created groups in a directory automatically go under sync management. After you enable editing, you can edit synced data in the Admin Console for a brief period. Any edits during this time do not affect user information in the Azure AD, but are overwritten by change requests from your identity provider.

    Caution:

    By default, you must edit synced data from the identity provider and allow the changes to propagate through sync. We do not recommend you to manually change data in Admin Console unless absolutely necessary.

  • Sync status: Instructs Azure Sync to reject change requests from Azure AD. Once the User Sync Status is Off, changes in Azure AD (user information source) are not pushed to the Adobe Admin Console. 

  • Edit user sync configuration: Redirects you to the configuration instructions to edit user sync. Use this if the modal is closed before completing the sync setup or if you must change things in Azure AD after the initial configuration.

Remove sync

Administrators can choose to remove sync from a federated directory within the Admin Console. Removing sync leaves the directory and its associated domains, user groups, and users intact, and removes read-only mode from the directory and its users and groups.

To remove sync from a directory, choose Go to Settings from the Directory settingsSync tab, then Remove Sync. This action will permanently remove the sync setup from the Admin Console. If needed, you can reestablish sync with the same or different directory.

Note:

Domains cannot be moved to or from a directory managed by Azure Sync within the same organization.  Once Azure Sync is removed from the source and/or target directory, a domain from that directory can be moved to another target directory, and domains from other source directories can be moved into the directory that is no longer managed by Azure Sync. 

Disable users and groups

Implementing Azure Sync creates new federated user accounts and syncs users to the Adobe Admin Console. Administrators can also deprovision users and groups added through Azure Sync via the below three methods (in the Microsoft Azure Portal):

  • Remove user from all synced groups in Azure AD

  • Soft delete user from Azure AD

  • Remove all groups that the user is part of from the provisioning scope in Azure AD

These three operations disable users in the Adobe Admin Console. A disabled user is no longer able to log in and shows as Disabled in the Directory Users list. Azure Sync will keep managing a user deprovisioned by one of these methods. Neither the user’s account nor cloud-stored assets are removed from the organization. 

Remove a user and associated data from the Admin Console: Choose Go to Settings from the Directory settings Sync tab and click Enable editing. Then navigate to Users > Directory Users and choose the user from the list to permanently delete the account.

Once editing is enabled, it allows edits in the synced data for one hour before getting automatically disabled. We recommend you to click Disable editing immediately after user removal to ensure that the Admin Console reflects Azure AD changes.

Caution:

If you permanently delete a user, the user is deleted along with all the cloud-stored assets belonging to that user. The user and the assets cannot be recovered once this action is taken.

Quarantine policy

Adobe and Microsoft have a quarantine policy to handle numerous error calls during sync operations. 

The Azure AD provisioning service monitors the health of your configuration and places unhealthy apps in a "quarantine" state. If most or all of the calls made against the target system consistently fail because of an error, for example, invalid admin credentials, the provisioning job is marked as in quarantine. While in quarantine, the frequency of incremental cycles is gradually reduced to once per day. The provisioning job is removed from quarantine after all errors are fixed and the next sync cycle starts. If the provisioning job stays in quarantine for more than four weeks, the provisioning job is disabled (stops running). Learn more about applications provisioning in quarantine status within Azure AD.

Adobe’s service independently monitors sync health to verify when the error rate surpasses a certain threshold in a set amount of time. A minimum number of requests resulting in an error that meets the threshold will enact temporary quarantine, resulting in rejecting all calls and update requests from Azure AD for a time period, after which calls will be accepted again for sync retry. If error calls persist, the sync will be placed on temporary probation for an extended time period in quarantine. If Adobe initiates the quarantine, it may also lead to a subsequent quarantine with Azure due to the rejected calls, which will count toward error rates in Azure. Note that Adobe reserves the right to update the quarantine parameters based on ongoing data analytics. 

Common error messages

There is a set of common error messages displayed to be aware of when managing Azure Sync from Azure AD. Understanding the cause of the various error messages will aid in troubleshooting when errors occur.

Learn more about monitoring your deployment within Azure AD.

Troubleshoot sync issue

As the Adobe Admin Console uses Microsoft’s Azure sync service, all sync issues are troubleshot within Azure AD. You can refer to Microsoft’s configuration instructions to solve some common issues. If you are unable to find a solution, we recommend you to contact Microsoft Support for further assistance.

Follow the instructions below to diagnose a sync issue:

  1. Confirm your user and group setup:

    Make sure you have configured the users and groups as per the setup instructions:

  2. Confirm mapping of the user details: Microsoft documentation.

  3. Monitor your provisioning application to uncover issues that may affect sync:

    If the users don't appear in the provisioning logs, they may be out of scope. If the provisioning logs show an issue, fix it to allow the user to sync. Microsoft documentation

  4. Powershell extensions:

    Use the Azure Powershell extensions to identify any issues with the user’s Azure AD record.

    Confirm the user data with the following Powershell commands. If you need time to accomplish these steps, enable editing mode in the admin console to make the temporary changes:

    1. Install-Module AzureAD
    2. Connect-AzureAD -Credential (Get-Credential)
    3. Get-AzureADUser -ObjectId <user's email address> | FL
  5. Allow editing synced data in Admin Console:

    After you enable editing, you can edit synced data in the Admin Console for a brief period. Any edits during this time do not affect user information in Azure AD. Later, your identity provider's change requests automatically overwrite these brief changes.

Manage existing user accounts

Additional steps are required to convert all existing non-Federated ID users to Federated ID type.

Caution:

DO NOT assign any products to the synced federated users when doing the edit identity switch. It should be done right after syncing but before any product assignment.

Users that have an existing non-Federated ID account in the Admin Console can be migrated to a Federated ID account once Azure Sync has been established. Once converted, Azure AD pushes these accounts to Adobe Admin Console successfully.

To ensure that any cloud-stored assets are migrated to the user’s new identity type, follow the process below:

  1. Set up Azure Sync for users who already have a non-Federated ID on the Adobe Admin Console. Any users with an existing non-Federated ID now have both a non-Federated ID and a Federated ID in the Adobe Admin Console.

  2. Follow the steps in Edit Identity Type by CSV to change non-Federated ID users to Federated ID type. Ensure to match the following details:

    • Match Username and Email fields with Username (UserPrincipalName) fields in Azure AD.
    • Match FirstName and LastName with the corresponding fields in Azure AD.

    Upon login with the new Federated ID,  the user will be prompted with an option to automatically migrate cloud-stored assets to the new account.

Next steps

Once you've added Azure Sync to your directory, all users and user groups are imported to the Adobe Admin Console and updated at regular intervals. Next, you've to enable these users to access their designated Adobe apps:

  1. Create and manage product profiles: Create appropriate product profiles and associate them with users and user groups to fine-tune who gets to use which Adobe apps and services. See how to manage products and product profiles.
  2. When users are assigned the designated products, they receive an email notification. Users can directly download and install the Creative Cloud Desktop App.
    If your users don't have admin permissions, you must create and deploy appropriate packages.
  3. Create and deploy packages: To provide access to the apps to your users, create and deploy the app packages on their computers. Users must sign in using their SSO credentials to start using the apps and services. For more information, see Create Named User Licensing Packages.

If you're the admin of an institution, after setting up Azure sync, we recommend that you enable role sync. Learn about Role sync for Education.

 Adobe

Dapatkan bantuan lebih cepat dan lebih mudah

Pengguna baru?

Adobe MAX 2024

Adobe MAX
Konferensi Kreativitas

14–16 Oktober Miami Beach dan online

Adobe MAX

Konferensi Kreativitas

14–16 Oktober Miami Beach dan online

Adobe MAX 2024

Adobe MAX
Konferensi Kreativitas

14–16 Oktober Miami Beach dan online

Adobe MAX

Konferensi Kreativitas

14–16 Oktober Miami Beach dan online