User Guide Cancel

Set up organization via directory trust

  1. Adobe Enterprise & Teams: Panduan administrasi
  2. Rencanakan penerapan Anda
    1. Konsep dasar
      1. Pemberian lisensi
      2. Identitas
      3. Manajemen pengguna
      4. Penerapan aplikasi
      5. Ikhtisar Admin Console
      6. Peran admin
    2. Panduan Penerapan
      1. Panduan penerapan Pengguna Bernama
      2. Panduan Penerapan SDL
      3. Terapkan Adobe Acrobat 
    3. Terapkan Creative Cloud for Education
      1. Beranda penerapan
      2. Wizard Orientasi K-12
      3. Penyiapan sederhana
      4. Menyinkronkan Pengguna
      5. Roster Sync K-12 (AS)
      6. Konsep pemberian lisensi utama
      7. Opsi penerapan
      8. Kiat ringkas
      9. Setujui aplikasi Adobe di Admin Console Google
      10. Aktifkan Adobe Express di Google Classroom
      11. Integrasi dengan Canvas LMS
      12. Integrasi dengan Blackboard Learn
      13. Mengonfigurasi SSO untuk Portal Distrik dan LMS
      14. Tambahkan pengguna melalui Roster Sync
      15. FAQ Kivuto
      16. Pedoman kelayakan institusi Primer dan Sekunder
  3. Atur organisasi Anda
    1. Tipe identitas | Ringkasan
    2. Atur identitas | Ringkasan
    3. Atur organisasi dengan Enterprise ID
    4. Atur federasi dan sinkronisasi Azure AD
      1. Atur SSO dengan Microsoft melalui Azure OIDC
      2. Tambahkan Azure Sync ke direktori Anda
      3. Sinkronisasi peran untuk Pendidikan
      4. FAQ Azure Connector
    5. Atur Google Federation dan sinkronkan
      1. Atur SSO dengan Google Federation
      2. Tambahkan Google Sync ke direktori Anda
      3. FAQ Google federation
    6. Atur organisasi dengan Microsoft ADFS
    7. Mengatur organisasi untuk Portal Distrik dan LMS
    8. Atur organisasi dengan Penyedia Identitas lainnya
      1. Buat direktori
      2. Verifikasi kepemilikan domain
      3. Tambahkan domain ke direktori
    9. Pertanyaan umum dan pemecahan masalah SSO
      1. Pertanyaan Umum SSO
      2. Pemecahan Masalah SSO
      3. Pertanyaan umum tentang pendidikan
  4. Kelola pengaturan organisasi Anda
    1. Kelola domain dan direktori yang ada
    2. Aktifkan pembuatan akun otomatis
    3. Atur organisasi melalui kepercayaan direktori
    4. Bermigrasi ke penyedia autentikasi baru 
    5. Pengaturan aset
    6. Pengaturan autentikasi
    7. Kontak privasi dan keamanan
    8. Pengaturan Console
    9. Mengelola enkripsi  
  5. Mengelola pengguna
    1. Ikhtisar
    2. Peran administratif
    3. Strategi manajemen pengguna
      1. Mengelola pengguna secara individu   
      2. Mengelola banyak pengguna (CSV Massal)
      3. User Sync Tool (UST)
      4. Microsoft Azure Sync
      5. Google Federation Sync
    4. Tetapkan lisensi ke pengguna Tim
    5. Manajemen pengguna dalam aplikasi untuk tim
      1. Mengelola tim Anda di Adobe Express
      2. Mengelola tim Anda di Adobe Acrobat
    6. Tambahkan pengguna dengan domain email yang cocok
    7. Mengubah jenis identitas pengguna
    8. Mengelola grup pengguna
    9. Mengelola pengguna direktori
    10. Mengelola pengembang
    11. Memigrasikan pengguna yang ada ke Adobe Admin Console
    12. Memigrasikan manajemen pengguna ke Adobe Admin Console
  6. Mengelola produk dan hak
    1. Mengelola produk dan profil produk
      1. Mengelola produk
      2. Beli produk dan lisensi
      3. Mengelola profil produk untuk pengguna perusahaan
      4. Mengelola aturan penugasan otomatis
      5. Beri hak kepada pengguna untuk melatih model kustom Firefly
      6. Meninjau permintaan produk
      7. Mengelola kebijakan layanan mandiri
      8. Mengelola integrasi aplikasi
      9. Mengelola izin produk di Admin Console  
      10. Mengaktifkan/menonaktifkan layanan untuk profil produk
      11. Aplikasi Tunggal | Creative Cloud untuk perusahaan
      12. Layanan opsional
    2. Mengelola lisensi Perangkat Bersama
      1. Yang baru
      2. Panduan penerapan
      3. Buat paket
      4. Pulihkan lisensi
      5. Kelola profil
      6. Toolkit pemberian lisensi
      7. FAQ Pemberian Lisensi Perangkat Bersama
  7. Mulai menggunakan Global Admin Console
    1. Mengadopsi administrasi global
    2. Memilih organisasi Anda
    3. Mengelola hierarki organisasi
    4. Mengelola profil produk
    5. Mengelola administrator
    6. Mengelola grup pengguna
    7. Memperbarui kebijakan organisasi
    8. Mengelola templat kebijakan
    9. Mengalokasikan produk ke organisasi turunan
    10. Menjalankan pekerjaan yang tertunda
    11. Menjelajahi wawasan
    12. Mengekspor atau mengimpor struktur organisasi
  8. Kelola penyimpanan dan aset
    1. Penyimpanan
      1. Kelola penyimpanan perusahaan
      2. Adobe Creative Cloud: Pembaruan pada penyimpanan
      3. Kelola penyimpanan Adobe
    2. Migrasi aset
      1. Migrasi Aset Otomatis
      2. FAQ Migrasi Aset Otomatis  
      3. Kelola aset yang ditransfer
    3. Klaim kembali aset dari pengguna
    4. Migrasi aset siswa | hanya untuk EDU
      1. Migrasi aset siswa otomatis
      2. Migrasikan aset Anda
  9. Kelola layanan
    1. Adobe Stock
      1. Paket kredit Adobe Stock untuk tim
      2. Adobe Stock untuk perusahaan
      3. Gunakan Adobe Stock untuk perusahaan
      4. Persetujuan Lisensi Adobe Stock
    2. Font khusus
    3. Adobe Asset Link
      1. Ikhtisar
      2. Buat grup pengguna
      3. Konfigurasikan Adobe Experience Manager Assets
      4. Konfigurasikan dan instal Adobe Asset Link
      5. Kelola aset
      6. Adobe Asset Link untuk XD
    4. Adobe Acrobat Sign
      1. Atur Adobe Acrobat Sign untuk perusahaan atau tim
      2. Adobe Acrobat Sign - Administrator fitur tim
      3. Kelola Adobe Acrobat Sign di Admin Console
    5. Creative Cloud untuk perusahaan - keanggotaan gratis
      1. Ikhtisar
  10. Terapkan aplikasi dan pembaruan
    1. Ikhtisar
      1. Menerapkan dan mengirimkan aplikasi dan pembaruan
      2. Paket untuk diterapkan
      3. Siapkan untuk menerapkan
    2. Buat paket
      1. Aplikasi paket melalui Admin Console
      2. Buat Paket Pemberian Lisensi Pengguna Bernama
      3. Templat Adobe untuk paket
      4. Kelola paket
      5. Kelola lisensi perangkat
      6. Pemberian lisensi nomor seri
    3. Sesuaikan paket
      1. Sesuaikan Aplikasi desktop Creative Cloud
      2. Sertakan ekstensi dalam paket Anda
    4. Terapkan Paket 
      1. Terapkan paket
      2. Terapkan paket Adobe menggunakan Microsoft Intune
      3. Terapkan paket Adobe dengan SCCM
      4. Terapkan paket Adobe dengan ARD
      5. Instal produk di folder Pengecualian
      6. Hapus instalan produk Creative Cloud
      7. Gunakan edisi perusahaan toolkit penyediaan Adobe
      8. Pengidentifikasi pemberian lisensi Adobe Creative Cloud
    5. Kelola pembaruan
      1. Ubah manajemen untuk pelanggan perusahaan dan tim Adobe
      2. Terapkan pembaruan
    6. Adobe Update Server Setup Tool (AUSST)
      1. Ikhtisar AUSST
      2. Atur server pembaruan internal
      3. Pertahankan server pembaruan internal
      4. Kasus penggunaan umum AUSST   
      5. Pecahkan masalah server pembaruan internal
    7. Adobe Remote Update Manager (RUM)
      1. Catatan rilis
      2. Gunakan Adobe Remote Update Manager
    8. Memecahkan masalah
      1. Memecahkan masalah kesalahan penginstalan dan penghapusan instalan aplikasi Creative Cloud
      2. Kueri mesin klien untuk memeriksa apakah suatu paket diterapkan
      3. Pesan kesalahan "Penginstalan Gagal" paket Creative Cloud
  11. Kelola akun Teams Anda
    1. Ikhtisar
    2. Memperbarui detail pembayaran
    3. Kelola faktur
    4. Ubah pemilik kontrak
    5. Ubah paket Anda
    6. Ubah pengecer
    7. Batalkan paket Anda
    8. Kepatuhan Permintaan Pembelian
  12. Perpanjangan
    1. Keanggotaan Teams: Perpanjangan
    2. Perusahaan di VIP: Perpanjangan dan kepatuhan
  13. Kelola kontrak
    1. Tahapan kedaluwarsa otomatis untuk kontrak ETLA
    2. Mengalihkan jenis kontrak dalam Adobe Admin Console yang ada
    3. Paket Insentif Nilai (VIP) di Tiongkok
    4. Bantuan Pemilihan VIP
  14. Laporan & log
    1. Log Audit
    2. Laporan tugas
    3. Log Konten
  15. Dapatkan bantuan
    1. Hubungi Layanan Pelanggan Adobe
    2. Opsi dukungan untuk akun tim
    3. Opsi dukungan untuk akun perusahaan
    4. Opsi dukungan untuk Experience Cloud

You can use directory trust to authenticate your users against a domain already claimed by another organization.

Directory trusting

Only one organization at a time can claim a domain's ownership. Thus, consider the following scenario:

A company, Geometrixx, has multiple departments, each of which has its own unique Admin Console. Also, each department wants to use Federated user IDs, all using the geometrixx.com domain.  Each department's system administrator would want to claim this domain for authentication.

The Admin Console prevents a domain from being added to multiple organizations' Admin Console. However, once added by a single department, other departments can request access to the directory to which that domain is linked on behalf of their organization's Admin Console.

Directory trusting allows a directory owner organization to trust other requesting organizations (trustees). After this, trustee organizations in the Admin Console can add users to any domain within the trusted directory.

To summarize, you must add a domain if you plan to use Enterprise ID or Federated ID on your Admin Console. If another organization has already added this domain, you must request trustee access to the directory containing this domain. However, when the trustee organization adds users to the trusted domains, they are authenticated based on the owning organization's identity management.

To request access to a directory, follow the steps in Add domains to directories.

Caution:
  • As an owner of a directory, if you approve an access request for a directory, the trustee organization will have access to all domains linked to the directory, as well as any domains linked to that directory in the future. So planning the domain-to-directory linking is essential as you set up the identity system in your organization.
  • Before adding, requesting, revoking, or withdrawing a trust request, we strongly recommend that you export a user list from the Admin Console or Consoles involved prior to making changes. This list will provide a snapshot of all user data, including name, email, assigned product profiles, and assigned admin roles in case you need to roll back.
  • There are specific steps to migrating a domain that includes a trust relationship. You should not revoke a trust relationship when migrating a trusted domain to prevent the loss of user account and product access in the trustee’s organization.

Domain trustee (Requesting organization)

Follow the process below if you want to request access to a directory owning your desired domain:

If you add existing domains to the Admin Console, you are prompted with the following message:

If you request access to this domain; your name, email, and organization name are shared with the system administrators of the owning organization.

Since the owner already set up the domain, you do not need to take any additional action as the trustee. When the owner accepts the access request, your organization can access the directory and all its domains, as configured by the owning organization.

  1. Sign in to the Admin Console and navigate to Settings > Identity.

  2. Go to the Access Requests tab and check the status against each directory for which you have requested access.

  3. You can also click the row item in the list of access requests and click Resend Request or Cancel Request.

If the owning organization accepts your request for access to the directory, you receive an email notification. Your trust request disappears and is replaced by the trusted directory and its domains with Active (trusted) status in your Directories and Domains listings.

Go ahead and add users and user groups and assign them to product profiles.

As the trustee organization, if you no longer have a need to access the trusted directory, you may withdraw your trustee status at any time.

  1. Sign in to the Admin Console and navigate to Settings > Identity.

  2. In the Directories tab, click the shared directory to withdraw your access from.

  3. In the directory details drawer, click Withdraw.

If you withdraw your access to a trusted directory, any users associated with the domains in that directory are removed from your organization. However, these users could still access their assigned apps, services, and storage.

To stop users from using the software, remove them from Admin Console > Users > Remove users. Then, you can reclaim the deleted users' assets since your organization owns these assets.

Domain owner (Owning organization)

When you get an email request for access to a directory you own, you can accept or reject the request from the email itself. Or, navigate to the Access request tab in the Admin Console to manage claim requests.

  1. Sign in to the Admin Console and navigate to Settings > Identity.

  2. Go to the Access Request tab.

  3. To accept all the requests, click Accept All.

    Or to accept requests for specific claims, click the check box to the left of each row and click Accept.

  4. In the Accept Access Request screen, click Accept.

An email notification is sent to the System admins of the trustee organizations.

You can also choose to reject the request for access to a directory that you own.

  1. Sign in to the Admin Console and navigate to Settings > Identity.

  2. Go to the Access Request tab.

  3. Click the check box to the left of each row and click Reject.

  4. In the Reject Access Request screen, enter a reason for the rejecting the request and click Reject.

The reason that you provide, is shared with the requesting organization via email. However, your email, name, and organizational information are withheld.

You can revoke the access of a trustee organization for which you have previously given access.

  1. Sign in to the Admin Console and navigate to Settings > Identity.

  2. Go to the Trustees tab.

  3. Click the check box to the left of each row and click Revoke.

  4. In the Revoke Trustee screen, click Revoke.

If you revoke access to a trusted directory, any users associated with the domains in that directory are removed from the trusted directory. However, these users could still access their assigned apps, services, and storage.

To stop users from using the software, trustee admins can remove them from Admin Console > Users Remove users. Then, they can reclaim the deleted users' assets since the trustee organization owns these assets.

Directory trusting - Common questions

When a user is added to a trustee organization, the user is authenticated by the owning organization's identity setup. This holds true for new users on the trustee organization or for existing users on the owning organization.

When the user on a trustee organization signs into Adobe apps or services, the user is prompted with the Federated ID or Enterprise ID sign-in workflow, as set up on the owning organization.

Also, the user may be given entitlements from either the owning or trustee organizations. In this case, we will create a profile for each organization (owning or trustee) to which the users belongs. A profile helps to keep entitlements and assets isolated from each organization. So, the assets created by a user under a specific profile belong to that organzation. If a user leaves an organization, the assets are reclaimed by the admin of that organization.

Read more:

After your trustee organization is migrated, all your users are signed out of their accounts and will need to sign back in. Since these users are also users in the owning organzation, they may be given entitlemnts from the owning as well as the trustee organizations. In this case, we will set up profiles for the users. So, when signing back into their accounts, your users may be prompted with a profile chooser.

If required, your users may read how to manage Adobe profiles.

 Adobe

Dapatkan bantuan lebih cepat dan lebih mudah

Pengguna baru?

Adobe MAX 2024

Adobe MAX
Konferensi Kreativitas

14–16 Oktober Miami Beach dan online

Adobe MAX

Konferensi Kreativitas

14–16 Oktober Miami Beach dan online

Adobe MAX 2024

Adobe MAX
Konferensi Kreativitas

14–16 Oktober Miami Beach dan online

Adobe MAX

Konferensi Kreativitas

14–16 Oktober Miami Beach dan online