-
Setup and onboarding
- Explore Adobe Admin Console
- Sign-in and access
-
Licensing
- Licensing overview
- Licensing types
-
Identity and SSO
- Set up identity
- Integrate with Microsoft Entra
- Integrate with Google Sync
- Integrate with other SSO providers
- Troubleshoot
-
Directories, domains, and access
-
Directories and domains
- Create a directory for SAML identity providers
- Verify domain ownership
- Set up domains for directory authentication
- Move domains across directories
- Encrypted and trusted directory domain transfers
- Move directories between Admin Consoles
- Delete directories and domains
- Automatic account creation overview
- Enable automatic account creation
- Automatic federated account creation FAQ
- Domain enforcement
- Directory trusting
-
Directories and domains
-
Settings
- Asset settings
- Manage encryption
-
User management
- Understand user management
- Manage users and groups
- Manage admins
- Manage user roles
- Migrate users
-
Products and entitlements
- Manage products
- Manage product profiles
- Special programs plans
- Manage entitlements
- Manage automatic assignment
- Manage product access
- Manage self-service policies
- Manage app integrations
- Frame.io integration
- Manage product permissions
- Manage storage and assets
-
Manage services
- Configure services
- Adobe Stock
- Custom fonts
- Adobe Asset Link
-
Deploy apps and updates
- Prepare for deployment
- Manage pre-generated packages
- Create packages
- Customize end-user experience
- Deploy packages
- Use third-party deployment tools
-
Manage Shared Device Licensing (SDL)
- Shared Device Licensing overview
- Deploy Shared Device Licensing
- Manage SDL profiles and user access
- Activate shared device licenses
- Use the Shared Device Licensing toolkit
- Recover shared device licenses
- Shared Device Licensing identity FAQ
- Shared Device Licensing deployment FAQ
- Shared Device Licensing access FAQ
- Known issues in Shared Device Licensing
- Adobe Update Server Setup Tool (AUSST)
- Adobe Remote Update Manager (RUM)
- Troubleshoot
- Contracts and renewals
- Reports and logs
-
Get started with Global Admin Console
- Get started
- Manage your organization
- Reports audit
-
Get help
- Support options
-
General troubleshooting
- Microsoft Purview Information Protection support in Acrobat
- Use the Creative Cloud Cleaner tool to fix installation issues
- Fix app launch errors on Shared Device Licensing machines
- Technical support boundaries for virtualized or server-based environments
- Resolve trial and license expired errors
- Migrating to OAuth Server-to-Server Credentials
- Manage device authentication for Creative Cloud and Acrobat Pro
Domain enforcement for restricted authentication
Understand how domain enforcement secures company email use and ensures consistent authentication.
Domain enforcement ensures company email addresses are used only with your organization’s identity system. It prevents users from creating personal Adobe accounts with work emails, giving your organization control and visibility while reducing risks.
Benefits of restricting domains
Domain enforcement provides several advantages:
- Block creation of new Adobe ID accounts: Restrict personal accounts with company emails.
- Create a consistent sign‑in workflow: Direct all sign-ins through the organization’s identity provider.
- Limit user accounts and profiles: Eliminate shadow accounts and duplicates.
- Improve collaboration among end users: Ensure asset sharing within the managed environment.
- Block purchase of software for personal use: Prevent unauthorized purchases with company emails.
Managing domain enforcement
Domain enforcement is enabled by default on all newly created Enterprise and Federated directories. Use it to control domain use in the following ways:
- Restrict the creation of Adobe ID accounts with organization-owned domains.
- Transition existing users with Adobe ID accounts to Enterprise ID or Federated ID accounts that require secure login for license and storage access.
- Generate reports indicating which users have Adobe ID accounts with enforced domains.
- Require existing Adobe ID accounts to change the email associated with the account to a personal address.
Domain enforcement best practices
Configure domains and directories strategically to align with your organization's authentication and security requirements.
Link domains to directories: To stop users associated with a particular domain from creating new accounts or using organization email for personal use, you must link the domains with domain-enforcement-enabled directories.
Transfer domains to a different directory: If you want to allow personal use of organization email for users associated with one or more domains, you must transfer these domains to one target directory. Then turn off domain enforcement for this target directory.
Allow automatic account creation: If you want users to create a Federated ID only with their email address, you must enable both domain enforcement and automatic account creation.