-
Setup and onboarding
- Explore Adobe Admin Console
- Sign-in and access
-
Plan your deployment
- Basic concepts
- Deployment Guides
-
Deploy Creative Cloud for education
- Education Deployment Home
- Education Deployment K-12 Onboarding Wizard
- Education Deployment Simple Setup
- Education Deployment Setup With User Sync
- Education Deployment Setup with Roster Sync
- Education Deployment Key licensing Concepts
- Education Deployment Setup Concepts
- Education Deployment Quick Tips
- Approve Adobe apps in Google Admin Console
- Enable Adobe Express in Google Classroom
- Integrate Adobe Creative Cloud and Adobe Express with Canvas LMS
- Adobe Creative Cloud & Blackboard Learn
- Configuring SSO for District Portals and Learning Management Systems
- Roster syncing for license assignment with the Adobe Admin Console
- Kivuto FAQ
- Primary and Secondary Institution Eligibility Guidelines
-
Licensing
- Licensing overview
- Licensing types
-
Set up your organization
- Identity overview
- Set up identity and Single Sign-On
- Set up organization with Enterprise ID
- Setup Azure AD federation and sync
- Set up Google Federation and sync
- Configure Microsoft AD FS for use with Adobe SSO
- Configuring SSO for District Portals and Learning Management Systems
- Set up organization with other Identity providers
- SSO common questions and troubleshooting
- Set up Frame.io for enterprise
-
Identity and SSO
- Set up identity
- Integrate with Microsoft Entra
- Integrate with Google Sync
- Integrate with other SSO providers
- Troubleshoot
-
Manage your organization setup
- Manage existing directories and domains
- Enable automatic account creation
- Domain Enforcement for restricted authentication
- Set up organization via directory trust
- Migrate to a new authentication provider
- Asset settings
- Manage authentication settings
- Limit product access by IP addresses
- Privacy and security contacts
- Console settings
- Manage encryption
-
Directories, domains, and access
-
Directories and domains
- Create a directory for SAML identity providers
- Verify domain ownership
- Set up domains for directory authentication
- Move domains across directories
- Encrypted and trusted directory domain transfers
- Move directories between Admin Consoles
- Delete directories and domains
- Automatic account creation overview
- Enable automatic account creation
- Automatic federated account creation FAQ
- Domain enforcement
- Directory trusting
-
Directories and domains
-
Manage users
- Adobe Admin Console users
- Administrative roles
- Assign user roles for granular access control
- How to create custom roles
- Manage Frame.io account roles in Adobe Admin Console
- User management strategies
- Assign a license to teams user
- Team Management: Creative Cloud desktop app, Acrobat, Express
- Adobe's matching service
- Edit user identity type
- Manage user groups
- Manage directory users
- Exclude specific users from domain enforcement
- Manage developers
- Migrate existing users to the Adobe Admin Console
- Migrate Frame.io user management to the Adobe Admin Console
- Admin roles and hierarchy
- Enterprise admin permissions matrix
-
Settings
- Asset settings
- Manage encryption
-
Manage products and entitlements
-
Manage products and product profiles
- Manage products on Admin Console
- Add products and licenses
- Manage product profiles for enterprise users
- Manage automatic assignment rules
- Adobe Express Photos FAQs for administrators
- Assign users to Firefly custom models
- Enable Shared Credits for your organization
- Manage product requests
- Manage self-service policies
- Manage app integrations
- Manage product permissions in the Admin Console
- Single App | Creative Cloud for enterprise
- Manage Shared Device licenses
-
Manage products and product profiles
-
User management
- Understand user management
- Manage users and groups
- Manage admins
- Manage user roles
- Migrate users
-
Get started with Global Admin Console
- Adopt global administration
- Select an organization in the Global Admin Console
- Manage organization hierarchy
- Manage product profiles
- Manage administrators
- Manage user groups
- Create license assignment reports for multiple organizations
- Update organization policies
- Manage policy templates
- Allocate products to child organizations
- Execute pending jobs
- Download audit logs and export reports
- Export or import organization structure and product allocations
-
Products and entitlements
- Manage products
- Manage product profiles
- Special programs plans
- Manage entitlements
- Manage automatic assignment
- Manage product access
- Manage self-service policies
- Manage app integrations
- Frame.io integration
- Manage product permissions
-
Manage storage and assets
- Storage
- Manage projects
- Asset migration
- Reclaim assets from a user
- Student asset migration | EDU only
- Manage storage and assets
-
Manage services
- Manage services in the Admin Console
- Configure services
- Optional services
- Adobe Stock
- Enable Shared Credits for your organization
- Custom fonts
-
Adobe Asset Link
- Adobe Asset Link
- Adobe Asset Link Overview
- Create user group for Adobe Asset Link
- Configure Experience Manager Assets as a Cloud Service
- Deploy Adobe Asset Link
- Configure Adobe Experience Manager 6.x Assets for Adobe Asset Link
- Manage assets using Adobe Asset Link
- Adobe Asset Link for Adobe XD
- Troubleshoot Adobe Asset Link
- Known issues with Adobe Asset Link
- Adobe Acrobat Sign
-
Deploy apps and updates
- Overview
-
Create packages
- Packaging apps via the Admin Console
- Create Named User Licensing Packages
- Manage pre-generated packages
- Manage Packages
- Customize packages
- Deploy Packages
- Manage updates
- Adobe Update Server Setup Tool (AUSST)
- Adobe Remote Update Manager (RUM)
-
Deploy apps and updates
- Prepare for deployment
- Manage pre-generated packages
- Create packages
- Customize end-user experience
- Deploy packages
- Use third-party deployment tools
-
Manage Shared Device Licensing (SDL)
- Shared Device Licensing overview
- Deploy Shared Device Licensing
- Manage SDL profiles and user access
- Activate shared device licenses
- Use the Shared Device Licensing toolkit
- Recover shared device licenses
- Shared Device Licensing identity FAQ
- Shared Device Licensing deployment FAQ
- Shared Device Licensing access FAQ
- Known issues in Shared Device Licensing
- Adobe Update Server Setup Tool (AUSST)
- Adobe Remote Update Manager (RUM)
- Troubleshoot
-
Manage your Teams account
- Manage your account
- Complimentary membership for team members
- Update payment details on your Teams account
- Download and email invoices
- Change the contract owner of your Teams account
- Change your Creative Cloud for teams plan
- Change reseller
- Cancel Creative Cloud for teams licenses
- Purchase Authorization Compliance
- Contracts and renewals
- Renewals
- Reports and logs
-
Manage contracts
- Automated expiration stages for ETLA contracts
- Switching contract types within an existing Adobe Admin Console
- Manage trials and special offers
- Complimentary membership for team members
- Creative Cloud for enterprise - free membership
- Frame.io and Creative Cloud for teams and enterprise plans
- Value Incentive Plan (VIP) in China
- VIP Select Help
-
Get started with Global Admin Console
- Get started
- Manage your organization
- Reports audit
-
Get help
- Enterprise and teams | Contact Adobe Customer Care
- Support options
- Teams | Support and Expert Sessions
-
General troubleshooting
- Microsoft Purview Information Protection support in Acrobat
- Use the Creative Cloud Cleaner tool to fix installation issues
- Fix app launch errors on Shared Device Licensing machines
- Technical support boundaries for virtualized or server-based environments
- Resolve trial and license expired errors
- Migrating to OAuth Server-to-Server Credentials
- Manage device authentication for Creative Cloud and Acrobat Pro
- Enterprise | Support and Expert Sessions
Introducing the Business Storage Model
Applies to enterprise & teams.
The Business Storage model gives a business control over assets their employees create, by assigning them cloud storage that is specifically owned by the business. Business Storage enables all kinds of new features for controlled sharing and collaboration. The new model provides significant business value, allowing companies to exert control over cloud data, mitigate IP risks, and reclaim assets when an employee leaves the company.
To achieve this, we created a new user account model that separates authentication from authorization.
- Authentication proves that you are who you say you are. When you log in with a username and password, you are authenticating.
- Authorization proves that you have the right to use the product or service you are trying to access. After authentication, the system checks a user's entitlement profile to determine whether that user is authorized.
An admin delegates access to a specific offering by adding users and groups to a product profile. Those users are authorized to use that product.
Previously, all authorization details for a user (including access to cloud storage) were kept with the user's authentication account. In the new model, the user's authentication information is kept in the user's account as before, but for business users, authorizations are kept in a separate business profile. This profile-only account associates an authentication account with an entitlement profile for a specific organization. For more details, see Understanding Profiles.
About Authentication Accounts
Authentication accounts associate an email address with login credentials (usually a password) that are stored at Adobe. They contain user-specific information such as the user's name and group memberships.
Anyone can have a personal Adobe ID account, whether or not they use it for business. The username is an email address in any unclaimed or public domain, and the credentials are controlled by the user, at account.adobe.com.
In the previous model, when Adobe teams and enterprise customers added Adobe ID users to their directories, entitlements delegated by the business were added directly to a profile in the user's account. In the new model, the business entitlements need to be kept separate, so that assets can be stored properly in the business-owned cloud storage.
When you are updated to the new model, existing Adobe ID users are moved to Enterprise storage, and their business authorizations are moved into the new account. They still own their Adobe ID account, and authenticate with their Adobe ID credentials.
Managed authentication accounts for enterprises
Enterprise customers can manage their users' authentication credentials using one of Adobe's Managed account types:
- Enterprise ID: If your organization has a claimed or trusted domain, you can use that domain to give users an Enterprise ID. These users will sign in using their organization email in your claimed domain.
- Federated ID: If your organization has also set up and integrated SSO with the Admin Console, your users can sign in using single sign-on with an email in a federated domain.
In Enterprise storage model, each of these managed ID users also has a Business account, which links their User Profile with their managed authentication account.
When you add managed users to a Console that has been updated, the system automatically assigns the correct type of authentication account (Enterprise or Federated) based on the user email domain--regardless of any Identity Type value you specify in a CSV file or UMAPI call.
Choosing Adobe Profiles
Cloud storage authorization can come from different sources. A user can have personal access; in fact, all Adobe IDs come with some personal cloud storage, and storage can be part of products and services that individuals purchase on their own. A business user can have authorization for both personal and business storage, and can even have authorization for business storage from different organizations.
In the previous model, there was no way to distinguish assets created with different authorization sources. Separating authentication accounts from authorization information allows the sign-in process to identify which profile is in use, and therefore whose cloud storage is used for work done in a particular session.
In the new model, all users still authenticate using their personal or managed credentials. If they potentially have multiple sources of authorization, they might also have to choose an entitlement profile for the specific organization they are working for at the time.
Multiple authorization sources
A user can have profiles in more than one organization, just as they can have authentication accounts in more than one organization. This means they might have more than one source of authorization for business storage. If so, they can choose the appropriate entitlement profile as part of the login workflow.
If an employee uses Adobe ID credentials to authenticate, they have a mix of personal and business authorizations. To make sure the business owns assets their employees create with the business license, the update process creates profile-only accounts for these users.
- As part of the update process, all assets that were previously associated with the personal account might be moved into business storage. To prepare for update, a user might have to download any personal assets and store them locally.
- The user will still use the Adobe ID credentials to authenticate, but they will then have to choose either their Personal Profile or the Organization Profile to complete the sign-in process.
Multiple authentication accounts
An email address in a federated domain (such as adobe.com) can be used for both an Adobe ID and a Federated ID in the same organization. When this happens, the user sees an account picker to choose which account to sign in with. Once they have chosen the account, they could see the profile picker to choose from profiles associated with that account.