-
Setup and onboarding
- Explore Adobe Admin Console
- Sign-in and access
-
Licensing
- Licensing overview
- Licensing types
-
Identity and SSO
- Set up identity
- Integrate with Microsoft Entra
- Integrate with Google Sync
- Integrate with other SSO providers
- Troubleshoot
-
Directories, domains, and access
-
Directories and domains
- Create a directory for SAML identity providers
- Verify domain ownership
- Set up domains for directory authentication
- Move domains across directories
- Encrypted and trusted directory domain transfers
- Move directories between Admin Consoles
- Delete directories and domains
- Automatic account creation overview
- Enable automatic account creation
- Automatic federated account creation FAQ
- Domain enforcement
- Directory trusting
-
Directories and domains
-
Settings
- Asset settings
- Manage encryption
-
User management
- Understand user management
- Manage users and groups
- Manage admins
- Manage user roles
- Migrate users
-
Products and entitlements
- Manage products
- Manage product profiles
- Special programs plans
- Manage entitlements
- Manage automatic assignment
- Manage product access
- Manage self-service policies
- Manage app integrations
- Frame.io integration
- Manage product permissions
- Manage storage and assets
-
Manage services
- Configure services
- Adobe Stock
- Custom fonts
- Adobe Asset Link
-
Deploy apps and updates
- Prepare for deployment
- Manage pre-generated packages
- Create packages
- Customize end-user experience
- Deploy packages
- Use third-party deployment tools
-
Manage Shared Device Licensing (SDL)
- Shared Device Licensing overview
- Deploy Shared Device Licensing
- Manage SDL profiles and user access
- Activate shared device licenses
- Use the Shared Device Licensing toolkit
- Recover shared device licenses
- Shared Device Licensing identity FAQ
- Shared Device Licensing deployment FAQ
- Shared Device Licensing access FAQ
- Known issues in Shared Device Licensing
- Adobe Update Server Setup Tool (AUSST)
- Adobe Remote Update Manager (RUM)
- Troubleshoot
- Contracts and renewals
- Reports and logs
-
Get started with Global Admin Console
- Get started
- Manage your organization
- Reports audit
-
Get help
- Support options
-
General troubleshooting
- Microsoft Purview Information Protection support in Acrobat
- Use the Creative Cloud Cleaner tool to fix installation issues
- Fix app launch errors on Shared Device Licensing machines
- Technical support boundaries for virtualized or server-based environments
- Resolve trial and license expired errors
- Migrating to OAuth Server-to-Server Credentials
- Manage device authentication for Creative Cloud and Acrobat Pro
Directory trusting overview
Learn how multiple organizations can share access to a single claimed domain through directory trust relationships.
Directory trusting lets organizations share domain access without duplicating ownership. Departments can manage their own Admin Consoles while using the same domain for authentication.
Directory ownership and trust
Adobe Admin Console allows only one organization to own a domain, which can be a roadblock when multiple departments need to use the same domain for Federated IDs.
Directory trusting allows domain owners to share access with other organizations. Once trust is granted, the other organizations can add users to the domain, while authentication stays under the owner's identity configuration. Identity settings remain centralized while departments manage users independently.
Directory trust relationships
Directory trusting links a domain owner with one or more trustees.
Owners claim the domain and set up identity using an Enterprise ID or a Federated ID.
Trustees request access through the standard domain-adding workflow in Settings > Identity. The request includes the trustee's organization name and the administrator's contact information, which Adobe shares with the owning organization. Once approved, trustees can create user accounts on the shared domain from their Admin Console.
Users always authenticate through the owner’s identity settings, while trustees assign products and manage entitlements.
Trust relationship management
Both the trustee and the owning organizations maintain control over their participation in trust relationships. Owners review incoming trustee requests in the Access Requests tab and can approve or reject each request individually or in bulk. If circumstances change, owners can revoke access. Trustees can also withdraw access to a directory if they no longer need it.
Revoking trust removes users tied to that directory from the trustee's Admin Console. Trustee admins should delete these users and, if necessary, reclaim assets.
Domain and directory planning considerations
Domain placement is important because approving an access request grants the trustee organization access to all current and future domains in that directory.
To migrate a domain in a trust relationship, follow the standard migration steps. Do not revoke trust, as it can cause account loss and disrupt product access.
Directory trust and user identity types
When a trustee adds users to a trusted directory, those users follow the identity type set by the owner, either Enterprise ID or Federated ID. They sign in using the owner’s authentication method.
If a user receives product licenses (entitlements) from both the owner and the trustee, separate profiles appear. These profiles keep assets and permissions distinct for each organization.
Each profile belongs to its organization, ensuring clear ownership and easy asset recovery when users leave.
Multi-organization user profiles and migration
When a trustee organization migrates its identity system, users must sign in again. Users who hold entitlements from both the owning and trustee organizations may encounter a profile chooser during this process, prompting them to select a Business Profile for each organization.
Profile separation ensures that assets created under a specific profile remain with the organization that granted those entitlements. When a user leaves an organization, the admin can reclaim the assets associated with that profile. Assets linked to other profiles remain accessible through the user’s other organizational memberships.
New user notification management
System administrators in the owning organization receive email notifications when trustees add users to the shared directory. These notifications apply to all admins and can be disabled in the Trustees section under Settings > Identity by turning off the New user notification toggle.