Panduan Pengguna Batal

Configure Microsoft AD FS for use with Adobe SSO

  1. Adobe Enterprise & Teams: Panduan pentadbiran
  2. Rancang pemasangan anda
    1. Konsep asas
      1. Pelesenan
      2. Identiti
      3. Pengurusan pengguna
      4. Pemasangan aplikasi
      5. Gambaran keseluruhan Admin Console
      6. Peranan pentadbir
    2. Panduan Pemasangan
      1. Panduan pemasangan Pengguna Bernama
      2. Panduan pemasangan SDL
      3. Pasangkan Adobe Acrobat 
    3. Pasangkan Creative Cloud untuk pendidikan
      1. Laman utama Penerapan
      2. Bestari Penyesuaian Tugas K-12
      3. Persediaan mudah
      4. Menyegerakkan Pengguna
      5. Penyegerakan Senarai K-12 (AS)
      6. Konsep pelesenan utama
      7. Pilihan penerapan
      8. Petua cepat
      9. Luluskan aplikasi Adobe dalam Google Admin Console
      10. Dayakan Adobe Express dalam Google Classroom
      11. Penyepaduan dengan Canvas LMS
      12. Penyepaduan dengan Blackboard Learn
      13. Mengkonfigurasikan SSO untuk District Portal dan LMS
      14. Tambahkan pengguna melalui Roster Sync
      15. Soalan Lazim Kivuto
      16. Garis panduan kelayakan institusi Utama dan Sekunder
  3. Sediakan organisasi anda
    1. Jenis identiti | Gambaran keseluruhan
    2. Sediakan identiti | Gambaran keseluruhan
    3. Sediakan organisasi dengan Enterprise ID
    4. Sediakan Azure AD federation dan segerakkan
      1. Sediakan SSO dengan Microsoft melalui Azure OIDC
      2. Tambahkan Azure Sync pada direktori anda
      3. Penyegerakan peranan untuk Pendidikan
      4. Soalan Lazim Azure Connector
    5. Sediakan Google Federation dan segerakkan
      1. Sediakan SSO dengan Google Federation
      2. Tambahkan Google Sync pada direktori anda
      3. Soalan Lazim Google federation
    6. Sediakan organisasi dengan Microsoft ADFS
    7. Sediakan organisasi untuk District Portal dan LMS
    8. Sediakan organisasi dengan penyedia Identiti lain
      1. Cipta direktori
      2. Sahkan pemilikan domain
      3. Tambahkan domain pada direktori
    9. Soalan lazim dan penyelesaian masalah SSO
      1. Soalan lazim SSO
      2. Penyelesaian masalah SSO
      3. Soalan lazim pendidikan
  4. Urus persediaan organisasi anda
    1. Urus domain dan direktori sedia ada
    2. Dayakan penciptaan akaun automatik
    3. Sediakan organisasi melalui amanah direktori
    4. Berhijrah kepada penyedia pengesahan baharu 
    5. Tetapan aset
    6. Tetapan pengesahan
    7. Hubungan privasi dan keselamatan
    8. Tetapan konsol
    9. Urus penyulitan  
  5. Urus pengguna
    1. Gambaran Keseluruhan
    2. Peranan pentadbiran
    3. Strategi pengurusan pengguna
      1. Urus pengguna secara individu   
      2. Urus berbilang pengguna (CSV Pukal)
      3. Alat Penyegerakan Pengguna (UST)
      4. Microsoft Azure Sync
      5. Google Federation Sync
    4. Berikan lesen kepada pengguna Pasukan
    5. Pengurusan pengguna dalam apl untuk pasukan
      1. Urus pasukan anda dalam Adobe Express
      2. Urus pasukan anda dalam Adobe Acrobat
    6. Tambahkan pengguna dengan domain e-mel yang sepadan
    7. Tukar jenis identiti pengguna
    8. Urus kumpulan pengguna
    9. Urus pengguna direktori
    10. Urus pembangun
    11. Hijrahkan pengguna sedia ada ke Adobe Admin Console
    12. Hijrahkan pengurusan pengguna ke Adobe Admin Console
  6. Urus produk dan kelayakan
    1. Urus produk dan profil produk
      1. Urus produk
      2. Beli produk dan lesen
      3. Urus profil produk untuk pengguna perusahaan
      4. Urus peraturan pemberian automatik
      5. Beri hak kepada pengguna untuk melatih model tersuai Firefly
      6. Semak permintaan produk
      7. Urus dasar layan diri
      8. Urus penyepaduan aplikasi
      9. Urus kebenaran produk dalam Admin Console  
      10. Dayakan/lumpuhkan perkhidmatan untuk profil produk
      11. Aplikasi Tunggal | Creative Cloud untuk perusahaan
      12. Perkhidmatan pilihan
    2. Urus lesen Peranti yang Dikongsi
      1. Apa yang baharu
      2. Panduan pemasangan
      3. Cipta pakej
      4. Pulihkan lesen
      5. Urus profil
      6. Kit alat pelesenan
      7. Soalan Lazim Pelesenan Peranti yang Dikongsi
  7. Bermula dengan Global Admin Console
    1. Amalkan pentadbiran global
    2. Pilih organisasi anda
    3. Urus hierarki organisasi
    4. Urus profil produk
    5. Urus pentadbir
    6. Urus kumpulan pengguna
    7. Kemas kini dasar organisasi
    8. Urus templat dasar
    9. Peruntukkan produk kepada organisasi anak
    10. Laksanakan kerja yang belum selesai
    11. Terokai insights
    12. Eksport atau import struktur organisasi
  8. Urus storan dan aset
    1. Storan
      1. Urus storan perusahaan
      2. Adobe Creative Cloud: Kemas kini kepada storan
      3. Urus storan Adobe
    2. Penghijrahan Aset
      1. Penghijrahan Aset Automatik
      2. Soalan Lazim Penghijrahan Aset Automatik  
      3. Urus aset yang dipindahkan
    3. Tuntut semula aset daripada pengguna
    4. Penghijrahan aset pelajar | EDU sahaja
      1. Penghijrahan aset pelajar automatik
      2. Hijrahkan aset anda
  9. Urus perkhidmatan
    1. Adobe Stock
      1. Pek kredit Adobe Stock untuk pasukan
      2. Adobe Stock untuk perusahaan
      3. Guna Adobe Stock untuk perusahaan
      4. Kelulusan Lesen Adobe Stock
    2. Fon tersuai
    3. Pautan Aset Adobe
      1. Gambaran Keseluruhan
      2. Cipta kumpulan pengguna
      3. Konfigurasikan Adobe Experience Manager Assets
      4. Konfigurasikan dan pasang Adobe Asset Link
      5. Urus aset
      6. Adobe Asset Link untuk XD
    4. Adobe Acrobat Sign
      1. Sediakan Adobe Acrobat Sign untuk perusahaan atau pasukan
      2. Adobe Acrobat Sign - Pentadbir ciri Pasukan
      3. Urus Adobe Acrobat Sign pada Admin Console
    5. Creative Cloud untuk perusahaan - keahlian percuma
      1. Gambaran Keseluruhan
  10. Pasangkan aplikasi dan kemas kini
    1. Gambaran Keseluruhan
      1. Pasangkan dan hantar aplikasi dan kemas kini
      2. Pelan untuk dipasangkan
      3. Bersedia untuk dipasangkan
    2. Cipta pakej
      1. Pakej aplikasi melalui Admin Console
      2. Cipta Pakej Pelesenan Pengguna Bernama
      3. Urus pakej yang dijana terlebih dahulu
        1. Urus templat Adobe
        2. Urus pakej aplikasi Tunggal
      4. Urus pakej
      5. Urus lesen peranti
      6. Pelesenan nombor siri
    3. Sesuaikan pakej
      1. Sesuaikan app desktop Creative Cloud
      2. Sertakan sambungan dalam pakej anda
    4. Pasangkan Pakej 
      1. Pasangkan pakej
      2. Pasangkan pakej Adobe menggunakan Microsoft Intune
      3. Pasangkan pakej Adobe dengan SCCM
      4. Pasangkan pakej Adobe dengan ARD
      5. Pasang produk dalam folder Pengecualian
      6. Nyahpasang produk Creative Cloud
      7. Gunakan kit alat peruntukan Adobe edisi perusahaan
    5. Urus kemas kini
      1. Tukar pengurusan untuk pelanggan Adobe enterprise and teams
      2. Pasangkan kemas kini
    6. Adobe Update Server Setup Tool (AUSST)
      1. Gambaran Keseluruhan AUSST
      2. Sediakan pelayan kemas kini dalaman
      3. Mengekalkan pelayan kemas kini dalaman
      4. Kes penggunaan biasa AUSST   
      5. Selesaikan masalah pelayan kemas kini dalaman
    7. Adobe Remote Update Manager (RUM)
      1. Nota keluaran
      2. Gunakan Adobe Remote Update Manager
    8. Selesaikan masalah
      1. Selesaikan masalah ralat pemasangan dan penyahpasangan aplikasi Creative Cloud
      2. Tanya mesin klien untuk menyemak sama ada pakej dipasangkan
  11. Urus akaun Pasukan anda
    1. Gambaran Keseluruhan
    2. Kemas kini butiran bayaran
    3. Uruskan invois
    4. Tukar pemilik kontrak
    5. Tukar pelan anda
    6. Tukar penjual semula
    7. Batalkan pelan anda
    8. Pematuhan Permintaan Pembelian
  12. Pembaharuan
    1. Keahlian pasukan: Pembaharuan
    2. Perusahaan dalam VIP: Pembaharuan dan pematuhan
  13. Urus kontrak
    1. Tahap tamat tempoh automatik untuk kontrak ETLA
    2. Menukar jenis kontrak dalam Adobe Admin Console sedia ada
    3. Value Incentive Plan (VIP) di China
    4. Bantuan VIP Select
  14. Laporan & log
    1. Log Audit
    2. Laporan pemberian
    3. Log Kandungan
  15. Dapatkan bantuan
    1. Hubungi Layanan Pelanggan Adobe
    2. Pilihan sokongan untuk akaun pasukan
    3. Pilihan sokongan untuk akaun perusahaan
    4. Pilihan sokongan untuk Experience Cloud

Overview

The document highlights the process to configure the Adobe Admin Console with a Microsoft AD FS server.

The Identity Provider does not have to be accessible from outside the corporate network, but if it is not, only workstations within the network (or connected via VPN) will be able to perform authentication to activate a license or sign in after deactivating their session.

Set up SSO with Microsoft AD FS (Watch: 17 min)
Nota:

Instructions and screenshots in this document are for AD FS version 3.0, but the same menus are present in AD FS 2.0.

Prerequisites

Before creating a directory for single sign-on using Microsoft AD FS, the following requirements must be met:

  • A Microsoft Windows Server installed with Microsoft AD FS and the latest operating system updates. If you want the users to use Adobe products with macOS, ensure that your server supports TLS version 1.2 and forward secrecy. To learn more about AD FS, see the Microsoft Identity and access document.
  • The server must be accessible from users' workstations (for example, via HTTPS).
  • Security certificate obtained from the AD FS server.
  • All Active Directory accounts, to be associated with a Creative Cloud for enterprise account, must have an email address listed within Active Directory.

Create a directory in the Adobe Admin Console

To configure single sign-on for your domain, you need to do the following: 

  1. Sign in to the Admin Console and start with creating a Federated ID directory, selecting Other SAML Providers as the identity provider. Download the Adobe metadata file from the Create directory wizard.
  2. Configure AD FS specifying the ACS URL and Entity ID, and download the IdP metadata file.
  3. Return to the Adobe Admin Console and upload the IdP metadata file in the Create directory wizard. Then, select Next, set up auto-account creation, and select Done.

To learn more about the details of each step, follow the hyperlinks.

Configure the AD FS server

To configure SAML integration with AD FS, perform the below steps:

Peringatan:

All subsequent steps must be repeated after any change to the values in the Adobe Admin Console for a given domain.

  1. Navigate within the AD FS Management application to AD FS -> Trust Relationships -> Relying Party Trusts and click Add Relying Party Trust to start the wizard.

  2. Click Start and select Import data from a relying party from a file, then browse to the location to which you copied the metadata from your Adobe Admin Console.

  3. Name your relying party trust and enter any additional notes as required.

    Click Next.

  4. Determine if multi-factor authentication is required and select the relevant option.

    Click Next.

  5. Determine if all users can log on via AD FS.

    Click Next.

  6. Review your settings.

    Click Next.

  7. Your relying party trust has been added.

    Leave the option ticked to open the Edit Claim Rules dialog to quickly access the next steps.

    Click Close.

  8. If the Edit Claim Rules wizard has not opened automatically, you can access it from the AD FS Management application under AD FS -> Trust Relationships -> Relying Party Trusts, by selecting your Adobe SSO relying party trust and clicking Edit Claim Rules... on the right-hand-side.

  9. Click Add rule and configure a rule using the template Send LDAP attributes as Claims for your attribute store, mapping the LDAP Attribute E-Mail-Addresses to Outgoing Claim Type E-Mail Address.

    Nota:

    As shown in the above screenshot, we suggest using email address as the primary identifier. You can also use the User Principal Name (UPN) field as the LDAP attribute sent in an assertion as the email address. However, we do not recommend this to configure Claim Rule.

    Often the UPN does not map to an email address, and will in many cases be different. This will most likely cause problems for notifications and sharing of assets within Creative Cloud.

  10. Click Finish to complete adding the transform claim rule.

  11. Again, using the Edit Claim Rules wizard, add a rule using the template. Transform an incoming claim to convert Incoming claims of type E-Mail Address with Outgoing Claim Type Name ID and Outgoing Name ID Format as Email, passing through all claim values.

  12. Click Finish to complete adding the transform claim rule.

  13. Using the Edit Claim Rules wizard, add a rule using the template Send Claims Using a Custom Rule containing the following rule:

    c:[Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname", Issuer == "AD AUTHORITY"] => issue(store = "Active Directory", types = ("Email", "FirstName", "LastName"), query = ";mail,givenName,sn;{0}", param = c.Value);

  14. Click Finish to complete the custom rule wizard.

  15. Click OK on the Edit Claim Rules dialog to complete adding these three rules to your relying party trust.

    Nota:

    The order of the claim rules is important; they must appear as shown here.

To avoid connectivity problems between systems where the clock differs by a small amount, set the default time skew to 2 minutes. For more information on time-skew, see the troubleshooting errors document.

Download the AD FS metadata file

  1. Open the AD FS Management application on your server, and within the folder AD FS > Service > Endpoints, select the Federation Metadata.

    Metadata location

  2. Use a browser to navigate to the URL provided against Federation Metadata and download the file. For example, https://<your AD FS hostname>/FederationMetadata/2007-06/FederationMetadata.xml.

    Nota:
    • Accept any warnings if prompted.
    • To know your Microrsoft AD FS hostname on a Windows operating system:
      Open Windows PowerShell > Run as Administrator > Type Get-AdfsProperties > Press enter > Look for your Hostname in the detailed list.

Upload IdP metadata file to Adobe Admin Console

To update the latest certificate, return to Adobe Admin Console window. Upload the metadata file downloaded from AD FS to the Add SAML profile screen and click Done.

Next steps: Complete setup to assign apps to users

Once you've set up your directory, do the following to enable your organization's users to use Adobe apps and services:

  1. Add and set up domains within the Admin Console.
  2. Associate the domains with the AD FS directory.
  3. (Optional) If your domains are already established within the Admin Console in another directory, transfer them directly to the newly created AD FS directory.
  4. Add product profiles to fine-tune the usage of your purchased plans.
  5. Test your SSO setup by adding a test user.
  6. Choose you user-management strategy and tools based on your requirements. Then, add users to the Admin Console and assign them to product profiles to get users started with their Adobe apps.

To learn more about other identity-related tools and techniques, see Set up identity.

Test Single Sign-on

Create a test user with active directory. Create an entry on the Admin Console for this user and assign it a license. Then, test logging in to Adobe.com to confirm that the relevant software is listed for download.

You can also test by logging in to Creative Cloud Desktop and from within an application such as Photoshop or Illustrator.

If you encounter problems, see our troubleshooting document. If you still require assistance with your single sign-on configuration, navigate to Support in the Adobe Admin console, and open a ticket with Customer Support.

Dapatkan bantuan dengan lebih pantas dan mudah

Pengguna baharu?