|
Item |
Details |
|
|---|---|---|
|
Prerequisites |
|
|
|
〇 |
Email address |
|
|
Custom attribute Note: For instructions on configuring a custom attribute, see here |
||
|
SP-side configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
Supports provisioning via API (account management possible in TrustLogin) |
|
|
Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts created in each system) |
|
|
Access method |
〇 |
SP-Initiated SSO |
|
ー |
IdP-Initiated SSO |
|
|
Device compatibility verification status |
〇 |
PC - Browser |
|
ー |
PC - Desktop app |
|
|
〇 |
iOS - Standard browser (Safari) |
|
|
ー |
iOS - In-app browser of the TrustLogin mobile app |
|
|
〇 |
iOS - Native app |
|
|
〇 |
Android - Standard browser (Chrome) |
|
|
ー |
Android - In-app browser of the TrustLogin mobile app |
|
|
〇 |
Android - Native app |
|
|
Other |
[Services covered by SAML] Desktop applications such as Photoshop, Illustrator, Premiere Pro, After Effects, InDesign, etc. Cloud services such as Adobe Express, Portfolio, Acrobat Sign, etc. Online features such as Creative Cloud storage, libraries, cloud documents, etc. Note: We have verified operation with Acrobat Sign. |
|
TrustLogin Admin Page Configuration
- Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
- Search on the "Register Corporate App" screen and select "Adobe Creative Cloud (SAML)".
- Obtain the metadata from "Download Metadata" under "Identity Provider Information".
Now, switch to the configuration on the Adobe Creative Cloud side.
Open the Adobe Admin Console in a separate window.
Adobe Creative Cloud Configuration
① Domain Configuration
- Log in to the Adobe Admin Console and click "Settings > Identity > Domains > Add Domain".
- Enter the domain subject to SSO and click "Next".
- Confirm the domain and click "Add Domain". Add the displayed DNS record to the domain.
- Open "Verify" for the added domain. Set the displayed DNS record on the domain.
Once the addition is complete, click "Verify Now".
Note: The method for configuring DNS records varies by domain registrar. Please refer to your domain registrar's help documentation. It may take up to 72 hours for DNS record changes to propagate. If verification is not successful right away, you can proceed to the next step, "Create a Directory", first.
- Once the DNS record has propagated and domain verification is complete, the status changes to "Directory Required".
② Creating a Directory and SAML Configuration
- Click "Settings > Identity > Directories > Create Directory".
- Set any name for "Directory Name", set "Directory Type" to "Federated ID", and proceed with "Next".
- Select "Other SAML Provider" and proceed with "Next".
- Obtain the metadata from "Download Adobe Metadata" in Step 1.
- Drag and drop the metadata obtained from TrustLogin into the box in Step 2, and proceed with "Next".
- Disable "Enable automatic account creation for this identity provider" and click the "Finish" button.
③ Link the Domain and Directory
- Return to "Settings > Identity > Domains" and click "Link to Directory" for the registered domain.
- Select the created directory from the drop-down list and click "Link".
- Confirm that the status has changed to "Active" and that the link completed successfully.
③ Adding Users
- Open the "Users" screen and click "Add User".
- Enter the email address in "Email Address or Username". (The email address must be the same as the TrustLogin email address and must be in the format "username@registered domain".)
Select "Federated ID (Recommended)" for the ID type; "Name" is optional; the "SSO Username" is automatically populated with the email address. Finally, click "Save".
- Open the details screen from the link for the created username, and assign products, user groups, and administrator privileges.
Return once again to the TrustLogin configuration screen.
TrustLogin Admin Page Configuration (Continued)
- From "Select Metadata" under "Service Provider Configuration", upload the metadata obtained from Adobe.
- Save by clicking the "Register" button.
TrustLogin User Configuration
① When a user adds the app from My Page
- Click the "Add App" button on "My Page".
- Select "Adobe Creative Cloud (SAML)" on the "Register App" screen, and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it, then click the "Register" button.
② When an administrator adds members
- Search for and click the "Adobe Creative Cloud (SAML)" app in the "Admin Page > Apps" menu.
- Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.
How to Log In to Adobe Products
Users can log in to their assigned Adobe products via SAML. Login is only possible via SP-Initiated; you cannot log in from the SAML app in TrustLogin.
- Open the login URL for the target Adobe product and enter only your ID (email address).
- When you place the cursor in the "Password" field, you will automatically be redirected to the TrustLogin login screen to authenticate. SAML login will then complete.
If you are already logged in to TrustLogin, login to the Adobe product will complete automatically.