Sign into Azure AD with an Admin account.
- Adobe Enterprise & Teams: Administration guide
- Plan your deployment
- Basic concepts
- Deployment Guides
- Deploy Creative Cloud for education
- Deployment home
- K-12 Onboarding Wizard
- Simple setup
- Syncing Users
- Roster Sync K-12 (US)
- Key licensing concepts
- Deployment options
- Quick tips
- Approve Adobe apps in Google Admin Console
- Enable Adobe Express in Google Classroom
- Integration with Canvas LMS
- Integration with Blackboard Learn
- Configuring SSO for District Portals and LMSs
- Add users through Roster Sync
- Kivuto FAQ
- Primary and Secondary institution eligibility guidelines
- Set up your organization
- Identity types | Overview
- Set up identity | Overview
- Set up organization with Enterprise ID
- Setup Azure AD federation and sync
- Set up Google Federation and sync
- Set up organization with Microsoft ADFS
- Set up organization for District Portals and LMS
- Set up organization with other Identity providers
- SSO common questions and troubleshooting
- Manage your organization setup
- Manage users
- Overview
- Administrative roles
- User management strategies
- Assign licenses to a Teams user
- In-app user management for teams
- Add users with matching email domains
- Change user's identity type
- Manage user groups
- Manage directory users
- Manage developers
- Migrate existing users to the Adobe Admin Console
- Migrate user management to the Adobe Admin Console
- Overview
- Manage products and entitlements
- Manage products and product profiles
- Manage products
- Buy products and licenses
- Manage product profiles for enterprise users
- Manage automatic assignment rules
- Entitle users to train Firefly custom models
- Review product requests
- Manage self-service policies
- Manage app integrations
- Manage product permissions in the Admin Console
- Enable/disable services for a product profile
- Single App | Creative Cloud for enterprise
- Optional services
- Manage Shared Device licenses
- Manage products and product profiles
- Get started with Global Admin Console
- Adopt global administration
- Select your organization
- Manage organization hierarchy
- Manage product profiles
- Manage administrators
- Manage user groups
- Update organization policies
- Manage policy templates
- Allocate products to child organizations
- Execute pending jobs
- Explore insights
- Export or import organization structure
- Manage storage and assets
- Storage
- Asset migration
- Reclaim assets from a user
- Student asset migration | EDU only
- Manage services
- Adobe Stock
- Custom fonts
- Adobe Asset Link
- Adobe Acrobat Sign
- Creative Cloud for enterprise - free membership
- Deploy apps and updates
- Overview
- Create packages
- Customize packages
- Deploy Packages
- Manage updates
- Adobe Update Server Setup Tool (AUSST)
- Adobe Remote Update Manager (RUM)
- Troubleshoot
- Manage your Teams account
- Renewals
- Manage contracts
- Reports & logs
- Get help
Applies to enterprise.
Overview
To enable tailored experiences, enhance security, and ensure compliance, admins now can add educator and student tags to users in the Adobe Admin Console for existing Azure syncs and new Azure setups. After you have set up an Azure sync, you can add an attribute mapping to indicate which users are educators and which are students.
In the future, these educator and student tags will allow Adobe to display tailored experiences to educators and students based on their role. For example, educators will be able to set up classrooms of their students and monitor progress on assignments, see lesson plans that are hidden from students, and more. To unlock these future educator-specific developments, please follow the steps below.
Prerequisites
- Microsoft Azure AD is set up in your institution.
- A distinct way to Identify Students and Educators (for example, teachers have JobTitle attribute filled out in Azure; students have unique email domain; student emails all start with similar prefix; etc.)
- Microsoft Azure Sync already set up to sync users in the Adobe Admin Console. Learn how to setup Azure sync.
Steps to perform role sync
-
-
Navigate to Enterprise Applications under Azure Active Directory.
-
Select the Adobe Identity Management app where you’ve configured Auto provisioning.
-
Select Provisioning.
-
Navigate to Edit Attribute Mapping.
-
Under the Mapping section, select Provision Azure Active Directory Users.
-
Then select Add New Mapping.
Apply Role mapping
To enable Adobe Express to provide a tailored experience for Educators and students we need to share role information from Azure AD to Adobe through the process of an attribute mapping.
A Direct Mapping of role from Azure AD to Adobe can only be used if you have an attribute that is Educator or Student for all users.
Expression mapping enables the use of a rule to generate the output of Educator or Student. In the following section we have provided examples with comments for common use cases in education.
A Direct Mapping of role from Azure AD to Adobe can only be used if you have an attribute that contains Educator or Student for all users. For example, if the Azure AD attribute Job title has the value Educator for teachers and Student for students. It can be mapped directly to the target attribute.
-
Select Direct Mapping Type.
-
Set Source attribute.
-
Set Target attribute.
-
Click OK.
-
Save mapping.
-
Select Save.
If an attribute such as employeeType is used to identify teachers verses students the following is an example expression that can be used to set role based on a list of values.
-
Select Expression Mapping type.
-
Build Expression.
//The following expression defaults to the Student role and assigns the Educator role when employeeType has a value of Faculty, Staff or Coach. Switch([employeeType], student, <teachers_employeeType>, Educator) Ex: employeeType = [Faculty, Staff, Coach...] Switch([employeeType], Student, Faculty, Educator, Staff, Educator, Coach, Educator)
-
Use Expression Builder to test attribute mapping.
-
Set Target attribute.
-
Click OK.
-
Save mapping.
-
Select Save.
If you distinguish role by email domain, an expression can be used to send the Educator role attribute based on @example.org. And send the Student role based on @student.example.org.
-
Select Expression Mapping type.
-
Build Expression.
// Users with an email address on the students domain will be marked as students. Users with email on the teachers domain will be marked as educators. Every other user will not be marked Switch(Item(Split([mail], "@"), 2), "", "<students_domain>", "Student", "<teachers_domain>", "Educator") Ex: student_domain = student.example.org Teacher_domain = example.org Switch(Item(Split([mail], “@”), 2), “”,“student.example.org”, “Student”, “example.org”, “Educator”)
-
Use Expression Builder to test attribute mapping.
-
Set Target attribute.
-
Click OK.
-
Save mapping.
-
Select Save.
If you distinguish role by UPN, an expression can be used to send the Educator role attribute based on @example.org. And the Student role based on @student.example.org.
-
Select Expression Mapping type.
-
Build Expression.
// UPN - Users who have a UPN based on the teacher's domain will be marked as teachers. Every other user will be marked as student Switch(Item(Split([userPrincipalName], "@"), 2), "student", "<teachers_domain>", "teacher") Ex: student_domain = student.example.org Teacher_domain = example.org Switch(Item(Split([userPrincipalName], "@"), 2),"student", "example.org", "Educator")
-
Use Expression Builder to test attribute mapping.
-
Set Target attribute.
-
Click OK.
-
Save mapping.
-
Select Save.
If you distinguish role based on an email prefix, such as s_username@students.example.org, an expression can be used to send the Student role attribute if s_ is present and the Educator role if not.
-
Select Expression Mapping type.
-
Build Expression.
// email prefix – Users with an “s_” email prefix will be marked as Student. All other users will be marked as Educator. Ex: Email address = s_johnson@student.example.org IIF(Left([mail], "2") = "s_", "Student", "Educator")
-
Use Expression Builder to test attribute mapping.
-
Set Target attribute.
-
Click OK.
-
Save mapping.
-
Select Save.
Test Role sync
Role Ingestion can be tested by provisioning a user on-demand or waiting for changes to begin flowing between Azure AD and Adobe.
Test Role Ingestion via on-demand provisioning
On-demand provision a user in Azure AD
-
Return to the Adobe Identity Management app.
-
Select Provision on demand.
-
Select User and click Provision.
-
Review Results.
Verify assignment
-
Sign in to the Admin Console.
-
In the Users tab, locate provisioned user.
-
Confirm role assignment.
View User Details.