How to Configure SAML Authentication for Adobe Creative Cloud

Item

Details

Prerequisites

  • Prior configuration on the Adobe Creative Cloud side is required.

  • For the latest setup instructions, please refer to the manual provided by Adobe Creative Cloud.

Email address

Custom attribute Note: For instructions on configuring a custom attribute, see here

SP-side configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts created in each system)
Note: For instructions on configuring provisioning, see here

Access method

SP-Initiated SSO

IdP-Initiated SSO

Device compatibility verification status

PC - Browser

PC - Desktop app

iOS - Standard browser (Safari)

iOS - In-app browser of the TrustLogin mobile app

iOS - Native app

Android - Standard browser (Chrome)

Android - In-app browser of the TrustLogin mobile app

Android - Native app

Other

[Services covered by SAML]

Desktop applications such as Photoshop, Illustrator, Premiere Pro, After Effects, InDesign, etc.

Cloud services such as Adobe Express, Portfolio, Acrobat Sign, etc.

Online features such as Creative Cloud storage, libraries, cloud documents, etc.

Note: We have verified operation with Acrobat Sign.
 For other services, please test them in your own environment.

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    idp01_.png

  2. Search on the "Register Corporate App" screen and select "Adobe Creative Cloud (SAML)".
    idp02.png

  3. Obtain the metadata from "Download Metadata" under "Identity Provider Information".
    idp03.png

Now, switch to the configuration on the Adobe Creative Cloud side.
Open the Adobe Admin Console in a separate window.

Adobe Creative Cloud Configuration

① Domain Configuration

  1. Log in to the Adobe Admin Console and click "Settings > Identity > Domains > Add Domain".
    01.png

  2. Enter the domain subject to SSO and click "Next".
    02.png

  3. Confirm the domain and click "Add Domain". Add the displayed DNS record to the domain.
    03.png

  4. Open "Verify" for the added domain. Set the displayed DNS record on the domain.
    Once the addition is complete, click "Verify Now".
    Note: The method for configuring DNS records varies by domain registrar. Please refer to your domain registrar's help documentation. It may take up to 72 hours for DNS record changes to propagate. If verification is not successful right away, you can proceed to the next step, "Create a Directory", first.
    domain04.png
    domain05.png

  5. Once the DNS record has propagated and domain verification is complete, the status changes to "Directory Required".
    domain06.png

② Creating a Directory and SAML Configuration

  1. Click "Settings > Identity > Directories > Create Directory".
    08.png

  2. Set any name for "Directory Name", set "Directory Type" to "Federated ID", and proceed with "Next".
    09.png

  3. Select "Other SAML Provider" and proceed with "Next".
    10.png

  4. Obtain the metadata from "Download Adobe Metadata" in Step 1.
    11.png

  5. Drag and drop the metadata obtained from TrustLogin into the box in Step 2, and proceed with "Next".
    12.png

  6. Disable "Enable automatic account creation for this identity provider" and click the "Finish" button.
    13.png

③ Link the Domain and Directory

  1. Return to "Settings > Identity > Domains" and click "Link to Directory" for the registered domain.
    14.png
  2. Select the created directory from the drop-down list and click "Link".
    15.png

  3. Confirm that the status has changed to "Active" and that the link completed successfully.
    16.png


③ Adding Users

  1. Open the "Users" screen and click "Add User".
    17.png

  2. Enter the email address in "Email Address or Username". (The email address must be the same as the TrustLogin email address and must be in the format "username@registered domain".)
    Select "Federated ID (Recommended)" for the ID type; "Name" is optional; the "SSO Username" is automatically populated with the email address. Finally, click "Save".
    18.png

  3. Open the details screen from the link for the created username, and assign products, user groups, and administrator privileges.
    19.png
    20.png

Return once again to the TrustLogin configuration screen.

TrustLogin Admin Page Configuration (Continued)

  1. From "Select Metadata" under "Service Provider Configuration", upload the metadata obtained from Adobe.
    21.png
  2. Save by clicking the "Register" button.

TrustLogin User Configuration

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. Select "Adobe Creative Cloud (SAML)" on the "Register App" screen, and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an administrator adds members

  1. Search for and click the "Adobe Creative Cloud (SAML)" app in the "Admin Page > Apps" menu.
  2. Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.

How to Log In to Adobe Products

Users can log in to their assigned Adobe products via SAML. Login is only possible via SP-Initiated; you cannot log in from the SAML app in TrustLogin.

  1. Open the login URL for the target Adobe product and enter only your ID (email address).
    login01.png

  2. When you place the cursor in the "Password" field, you will automatically be redirected to the TrustLogin login screen to authenticate. SAML login will then complete.
    If you are already logged in to TrustLogin, login to the Adobe product will complete automatically.

How to Configure SAML Authentication for Adobe Creative Cloud

Item

Details

Prerequisites

  • Prior configuration on the Adobe Creative Cloud side is required.

  • For the latest setup instructions, please refer to the manual provided by Adobe Creative Cloud.

Email address

Custom attribute Note: For instructions on configuring a custom attribute, see here

SP-side configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts created in each system)
Note: For instructions on configuring provisioning, see here

Access method

SP-Initiated SSO

IdP-Initiated SSO

Device compatibility verification status

PC - Browser

PC - Desktop app

iOS - Standard browser (Safari)

iOS - In-app browser of the TrustLogin mobile app

iOS - Native app

Android - Standard browser (Chrome)

Android - In-app browser of the TrustLogin mobile app

Android - Native app

Other

[Services covered by SAML]

Desktop applications such as Photoshop, Illustrator, Premiere Pro, After Effects, InDesign, etc.

Cloud services such as Adobe Express, Portfolio, Acrobat Sign, etc.

Online features such as Creative Cloud storage, libraries, cloud documents, etc.

Note: We have verified operation with Acrobat Sign.
 For other services, please test them in your own environment.

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    idp01_.png

  2. Search on the "Register Corporate App" screen and select "Adobe Creative Cloud (SAML)".
    idp02.png

  3. Obtain the metadata from "Download Metadata" under "Identity Provider Information".
    idp03.png

Now, switch to the configuration on the Adobe Creative Cloud side.
Open the Adobe Admin Console in a separate window.

Adobe Creative Cloud Configuration

① Domain Configuration

  1. Log in to the Adobe Admin Console and click "Settings > Identity > Domains > Add Domain".
    01.png

  2. Enter the domain subject to SSO and click "Next".
    02.png

  3. Confirm the domain and click "Add Domain". Add the displayed DNS record to the domain.
    03.png

  4. Open "Verify" for the added domain. Set the displayed DNS record on the domain.
    Once the addition is complete, click "Verify Now".
    Note: The method for configuring DNS records varies by domain registrar. Please refer to your domain registrar's help documentation. It may take up to 72 hours for DNS record changes to propagate. If verification is not successful right away, you can proceed to the next step, "Create a Directory", first.
    domain04.png
    domain05.png

  5. Once the DNS record has propagated and domain verification is complete, the status changes to "Directory Required".
    domain06.png

② Creating a Directory and SAML Configuration

  1. Click "Settings > Identity > Directories > Create Directory".
    08.png

  2. Set any name for "Directory Name", set "Directory Type" to "Federated ID", and proceed with "Next".
    09.png

  3. Select "Other SAML Provider" and proceed with "Next".
    10.png

  4. Obtain the metadata from "Download Adobe Metadata" in Step 1.
    11.png

  5. Drag and drop the metadata obtained from TrustLogin into the box in Step 2, and proceed with "Next".
    12.png

  6. Disable "Enable automatic account creation for this identity provider" and click the "Finish" button.
    13.png

③ Link the Domain and Directory

  1. Return to "Settings > Identity > Domains" and click "Link to Directory" for the registered domain.
    14.png
  2. Select the created directory from the drop-down list and click "Link".
    15.png

  3. Confirm that the status has changed to "Active" and that the link completed successfully.
    16.png


③ Adding Users

  1. Open the "Users" screen and click "Add User".
    17.png

  2. Enter the email address in "Email Address or Username". (The email address must be the same as the TrustLogin email address and must be in the format "username@registered domain".)
    Select "Federated ID (Recommended)" for the ID type; "Name" is optional; the "SSO Username" is automatically populated with the email address. Finally, click "Save".
    18.png

  3. Open the details screen from the link for the created username, and assign products, user groups, and administrator privileges.
    19.png
    20.png

Return once again to the TrustLogin configuration screen.

TrustLogin Admin Page Configuration (Continued)

  1. From "Select Metadata" under "Service Provider Configuration", upload the metadata obtained from Adobe.
    21.png
  2. Save by clicking the "Register" button.

TrustLogin User Configuration

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. Select "Adobe Creative Cloud (SAML)" on the "Register App" screen, and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an administrator adds members

  1. Search for and click the "Adobe Creative Cloud (SAML)" app in the "Admin Page > Apps" menu.
  2. Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.

How to Log In to Adobe Products

Users can log in to their assigned Adobe products via SAML. Login is only possible via SP-Initiated; you cannot log in from the SAML app in TrustLogin.

  1. Open the login URL for the target Adobe product and enter only your ID (email address).
    login01.png

  2. When you place the cursor in the "Password" field, you will automatically be redirected to the TrustLogin login screen to authenticate. SAML login will then complete.
    If you are already logged in to TrustLogin, login to the Adobe product will complete automatically.