When to use Enterprise ID accounts
Configure Adobe ID or Enterprise ID accounts to authenticate users without Single Sign-On integration.
Organizations without SSO can authenticate users with Adobe ID or Enterprise ID through the Admin Console by using Adobe's built-in authentication.
Choose your identity type
Your organization can use Adobe ID accounts, Enterprise ID accounts, or a combination of both depending on your control and data governance requirements.
Adobe ID accounts are created and managed by individual users, with Adobe handling user sign-in while organizations control assets and data. Enterprise ID accounts are created and owned by the organization. Adobe hosts the directory and manages user sign-in, and administrators have complete control of accounts and data. Enterprise ID offers stronger administrative oversight without requiring SSO.
The following table describes when to use Enterprise ID accounts and what they offer:
|
|
What Enterprise ID accounts offer |
|
Control apps and services available to a user |
Password-based user access |
|
Access to files and data associated with a user ID |
No approval requirements |
|
Block or delete a user account |
No configuration requirements |
Set up an Enterprise ID directory
Use this procedure to create an identity infrastructure based on Enterprise ID accounts.
Create a directory
Sign in to the Adobe Admin Console and navigate to Settings > Identity.
Navigate to the Directories tab and select Create Directory.
In the Create a Directory screen, enter a name for the directory.
Choose the Enterprise ID, then select Create Directory.
Add and manage domains
Link domains that your organization owns or trusts to your directory. Adobe authenticates your users against these domains. You must link claimed domains to the respective directories before adding users.
Set up domains in the Adobe Admin Console using one of these methods:
- Add a claimed domain to verify ownership through DNS records.
- Add a trusted domain to use domains claimed by another Adobe organization.
Link the domains to the directories based on how you want to share entitlements.
You can link multiple domains to the same directory or move domains across directories as needed.
Domain claiming requires DNS administrator access to add TXT records that verify your organization's ownership.
Add users and assign products
After configuring your directory and domains, add users and provide access to Adobe products and services.
Add users to the Adobe Admin Console using the desired user management approach.
Assign users to product profiles to provision access to your organization's Adobe products and services.
Optionally, use user groups to simplify product assignment for users who need identical entitlements.