Adobe Creative Cloud SAML JIT Setup Guide

Item

Details

Prior Confirmation

  • Prior configuration in Adobe Creative Cloud is required.

  • For the latest setup instructions, please check the manual provided by Adobe Creative Cloud.

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management possible in TrustLogin)

SAML JIT Provisioning supported (account management possible in TrustLogin; user deletion not supported)
Note: For setup instructions when provisioning is not required, see here

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Other

<Services covered by SAML>

Desktop applications such as Photoshop, Illustrator, Premiere Pro, After Effects,
and InDesign

Cloud services such as Adobe Express, Portfolio, and Acrobat Sign

Online features such as Creative Cloud storage, libraries, and cloud documents

Note: We have verified operation with Acrobat Sign.
 For other services, please test in your own environment.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    idp01_.png

  2. Search on the "Register Company App" screen and select "Adobe Creative Cloud (SAML)".
    idp02.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".
    idp03.png

Now, switch to configuring the Adobe Creative Cloud side.
Please open Adobe Admin Console in a separate window.

Adobe Creative Cloud Configuration

① Domain Configuration

  1. Log in to Adobe Admin Console and click "Settings > Identity > Domains > Add domain".
    01.png

  2. Enter the domain to be used for SSO and click "Next".
    02.png

  3. Confirm the domain and click "Add domain". Add the displayed DNS record to the domain.
    03.png

  4. Open "Verify" for the added domain. Set the displayed DNS record on the domain.
    Once the addition is complete, click "Verify now".
    Note: How to configure the DNS record varies depending on your domain registrar. Please refer to your domain registrar's help documentation. It may take up to 72 hours for DNS record changes to propagate. If verification does not succeed right away, you can also proceed to the next step, "Create Directory", first.
    domain04.png
    domain05.png

  5. Once the DNS record has propagated and domain verification is complete, the status changes to "Directory needed".
    domain06.png

② Create Directory and Configure SAML

  1. Click "Settings > Identity > Directories > Create directory".
    08.png

  2. Set any name you like for "Directory name", set "Directory type" to "Federated ID", and proceed by clicking "Next".
    09.png

  3. Select "Other SAML provider" and proceed by clicking "Next".
    10.png

  4. Download the metadata from "Download Adobe metadata" in Step 1.
    11.png

  5. Drag and drop the metadata obtained from TrustLogin into the box in Step 2, and proceed by clicking "Next".
    12.png

  6. Enable "Enable automatic account creation for this identity provider".
    Select the settings for "Default country" and "Update Admin Console user information when the user logs in (Note)" from the dropdowns, and click the "Done" button.
    Note: By selecting "Always update", the TrustLogin user information (the user's first and last name) will be synced each time the user logs in via TrustLogin.
    13-1.png
    13-2.png

③ Link the Domain and Directory

  1. Return to "Settings > Identity > Domains" and click "Link to directory" for the domain you registered.
    14.png

  2. Select the directory you created from the dropdown and click "Link".
    15.png

  3. Confirm that the status changes to "Active", indicating the link was completed successfully.
    16.png

Now return to the TrustLogin settings screen again.

TrustLogin Admin Page Settings (Continued)

  1. Upload the metadata obtained from Adobe via "Select Metadata" under "Service Provider Settings".
    21.png

  2. Click the "Save" button to save your settings.

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Adobe Creative Cloud (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Save" button.

② When an administrator adds members

  1. Search for and click the "Adobe Creative Cloud (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Save" button to add them.

How to Create an Account Using SAML JIT

  1. Users who do not have a federated account in Adobe should access the Adobe homepage and click "Log in" in the upper right.
    AdobeID01.png

  2. Enter your TrustLogin email address in the "Email address" field and click "Continue".
    Note: The domain of the email address must be a domain linked to the federated directory.AdobeID02.png


  3. You will be redirected to the TrustLogin login screen to authenticate. If you are already logged in to TrustLogin, SAML login will be completed and an account will be created in Adobe.

    Note: To use Adobe products, users must be assigned a product. You will need to separately configure automatic assignment rules, or submit a product request to the system administrator. For details, please refer to Adobe's documentation.

How to Log in to Adobe Products

Users can log in via SAML to their assigned Adobe products. Only SP-Initiated login is available; login is not possible from the SAML app in TrustLogin.

  1. Open the login URL for the target Adobe product and enter your ID (email address).
    login01.png

  2. When you place the cursor in the "Password" field, you will automatically be redirected to the TrustLogin login screen to authenticate. SAML login will then be completed.
    If you are already logged in to TrustLogin, login to the Adobe product will be completed automatically.

Adobe Creative Cloud SAML JIT Setup Guide

Item

Details

Prior Confirmation

  • Prior configuration in Adobe Creative Cloud is required.

  • For the latest setup instructions, please check the manual provided by Adobe Creative Cloud.

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management possible in TrustLogin)

SAML JIT Provisioning supported (account management possible in TrustLogin; user deletion not supported)
Note: For setup instructions when provisioning is not required, see here

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Other

<Services covered by SAML>

Desktop applications such as Photoshop, Illustrator, Premiere Pro, After Effects,
and InDesign

Cloud services such as Adobe Express, Portfolio, and Acrobat Sign

Online features such as Creative Cloud storage, libraries, and cloud documents

Note: We have verified operation with Acrobat Sign.
 For other services, please test in your own environment.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    idp01_.png

  2. Search on the "Register Company App" screen and select "Adobe Creative Cloud (SAML)".
    idp02.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".
    idp03.png

Now, switch to configuring the Adobe Creative Cloud side.
Please open Adobe Admin Console in a separate window.

Adobe Creative Cloud Configuration

① Domain Configuration

  1. Log in to Adobe Admin Console and click "Settings > Identity > Domains > Add domain".
    01.png

  2. Enter the domain to be used for SSO and click "Next".
    02.png

  3. Confirm the domain and click "Add domain". Add the displayed DNS record to the domain.
    03.png

  4. Open "Verify" for the added domain. Set the displayed DNS record on the domain.
    Once the addition is complete, click "Verify now".
    Note: How to configure the DNS record varies depending on your domain registrar. Please refer to your domain registrar's help documentation. It may take up to 72 hours for DNS record changes to propagate. If verification does not succeed right away, you can also proceed to the next step, "Create Directory", first.
    domain04.png
    domain05.png

  5. Once the DNS record has propagated and domain verification is complete, the status changes to "Directory needed".
    domain06.png

② Create Directory and Configure SAML

  1. Click "Settings > Identity > Directories > Create directory".
    08.png

  2. Set any name you like for "Directory name", set "Directory type" to "Federated ID", and proceed by clicking "Next".
    09.png

  3. Select "Other SAML provider" and proceed by clicking "Next".
    10.png

  4. Download the metadata from "Download Adobe metadata" in Step 1.
    11.png

  5. Drag and drop the metadata obtained from TrustLogin into the box in Step 2, and proceed by clicking "Next".
    12.png

  6. Enable "Enable automatic account creation for this identity provider".
    Select the settings for "Default country" and "Update Admin Console user information when the user logs in (Note)" from the dropdowns, and click the "Done" button.
    Note: By selecting "Always update", the TrustLogin user information (the user's first and last name) will be synced each time the user logs in via TrustLogin.
    13-1.png
    13-2.png

③ Link the Domain and Directory

  1. Return to "Settings > Identity > Domains" and click "Link to directory" for the domain you registered.
    14.png

  2. Select the directory you created from the dropdown and click "Link".
    15.png

  3. Confirm that the status changes to "Active", indicating the link was completed successfully.
    16.png

Now return to the TrustLogin settings screen again.

TrustLogin Admin Page Settings (Continued)

  1. Upload the metadata obtained from Adobe via "Select Metadata" under "Service Provider Settings".
    21.png

  2. Click the "Save" button to save your settings.

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Adobe Creative Cloud (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Save" button.

② When an administrator adds members

  1. Search for and click the "Adobe Creative Cloud (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Save" button to add them.

How to Create an Account Using SAML JIT

  1. Users who do not have a federated account in Adobe should access the Adobe homepage and click "Log in" in the upper right.
    AdobeID01.png

  2. Enter your TrustLogin email address in the "Email address" field and click "Continue".
    Note: The domain of the email address must be a domain linked to the federated directory.AdobeID02.png


  3. You will be redirected to the TrustLogin login screen to authenticate. If you are already logged in to TrustLogin, SAML login will be completed and an account will be created in Adobe.

    Note: To use Adobe products, users must be assigned a product. You will need to separately configure automatic assignment rules, or submit a product request to the system administrator. For details, please refer to Adobe's documentation.

How to Log in to Adobe Products

Users can log in via SAML to their assigned Adobe products. Only SP-Initiated login is available; login is not possible from the SAML app in TrustLogin.

  1. Open the login URL for the target Adobe product and enter your ID (email address).
    login01.png

  2. When you place the cursor in the "Password" field, you will automatically be redirected to the TrustLogin login screen to authenticate. SAML login will then be completed.
    If you are already logged in to TrustLogin, login to the Adobe product will be completed automatically.