Jump to content

Recommended Posts

Posted

I'm guessing this isn't possible.

 

Finally bit the bullet, and have switched from Device based activation (which worked brilliantly), to the new shared device activation that Adobe are needlessly enforcing for CC 2019.

 

Set it up with ADFS and have successfully imported all the users, and they can log in with their domain details.

 

That is fine, except now there is the added hassle of every user having to log in manually to CC every time they change computers. To make matters worse, the username and password dialogue box asks for your email address, then redirects to the ADFS logon page, and asks for your email address again, so users have to type in their whole email address twice!

 

I don't suppose anyone is aware of a way to automate the sign in based on domain credentials?

Posted

I'm just in the early planning stages for this. I've set up Azure AD for SSO in the Adobe Creative Cloud Enterprise App settings and have validated our domain in the Adobe Admin portal. I thought that it would then allow students to login automatically with their domain credentials but I'm guessing from your comments that it doesn't work properly?

 

I followed these documents:

 

https://helpx.adobe.com/uk/enterprise/kb/configure-microsoft-azure-with-adobe-sso.html

https://docs.microsoft.com/en-us/azure/active-directory/saas-apps/adobe-creative-cloud-tutorial

  • Thanks 1
Posted

The following blog post may answer your question (even though it is for Macs).

 

https://soundmacguy.wordpress.com/2019/02/01/adobe-shared-device-licensing-answers-to-questions-you-probably-didnt-want-to-ask

 

I use federated Adobe IDs for my users. My Macs are AD-joined, or I have NoMAD, so they have a Kerberos ticket. Does SDL leverage this to automatically sign in/activate?

Sort of. This is assuming you’re all set up with federated IDs and you have working SSO between your IdP (e.g. ADFS/Azure) and Adobe. The first time you launch an app (e.g Photoshop), you’ll see the regular sign-in window. If you enter any email address with your domain on the end (even with a user that doesn’t exist), you’re punted over to your IdP’s sign-in page where the Kerberos ticket for the user who’s logged in to the Mac is automatically used instead. No password prompt, straight through. You can’t actually sign in as any other federated user unless you blast things with kdestroy.

 

The apps behave as above if you sign in directly and the Creative Cloud Desktop App (CCDA – the bit that sits in the menu bar) will sign in by itself after you sign in to an app. BUT – if you try to sign into the CCDA itself first, it doesn’t use the Kerberos ticket. You’ll just get redirected to your IdP’s sign-in page and have to enter your credentials there to proceed.

  • Thanks 1
Posted

Hmm, thanks for that Arthur. Interesting. I'm wondering if it's different on PC, or if there is something wrong with our ADFS setup, as it's not auto logging in at that stage, even if we launch directly into Photoshop. I'll investigate that.

 

Colly, not sure if you've got that far yet, but even when it's connected to your domain for single sign on, it seems to me that you still need to manually import all the users from a CSV to allow them to log in, otherwise you just get permission denied.

Posted
Hmm, thanks for that Arthur. Interesting. I'm wondering if it's different on PC, or if there is something wrong with our ADFS setup, as it's not auto logging in at that stage, even if we launch directly into Photoshop. I'll investigate that.

 

Colly, not sure if you've got that far yet, but even when it's connected to your domain for single sign on, it seems to me that you still need to manually import all the users from a CSV to allow them to log in, otherwise you just get permission denied.

 

Is it not possible just to add in the users from the Create Cloud Application in the Azure Portal?

 

ADAdobe.jpg

Posted

Hello!

 

Found this post after noticing some referrals from it to my blog. :) If you want to automate the creation of users in the Adobe Admin Console from your directory service, you'll need to use the User Sync Tool - I did a session on it at our last London Apple Admins meetup (although it's pretty much platform agnostic). https://soundmacguy.wordpress.com/2019/02/21/the-adobe-user-sync-tool-ive-got-that-syncing-feeling/

Posted
I've done it with AzureAD but auth is via ADFS. You have to put the domain name into the login box to trigger the SSO. I asked Adobe and they said theres not way to automate this. Which is strange as Microsoft can do it with Office. The login box is actually using chrome when logged in according to AzureAD.
Posted

SDL lets you sign in with any account (free adobe id, federated user, paid personal account etc if you allow it in the adminconsole). When you use any of these account types on a pc with the SDL version installed you get the full functionality in the app including cloud services of the institutions license. Benefit of this is students can use they own personal adobe id accounts and access their resources.

 

Currently it doesn’t pull in the logged in ad users account due to the ability to use any account but when you type on a federated email it will redirect and signin automatically if you have your users synced to the adminconsole.

 

Unlike the old adobe device license signin this doesn’t break the adobe license on the pc.

  • 3 weeks later...
Posted
The lack of auto sign in for this is quite frankly, beyond stupid. There's a reason many of us go the extra mile to make sure things like Office sign in with no fuss & that adobe go backwards on this is nuts.
Posted
All they need is a text file or registry key to populate the login screen. It could just be an append to the URL to add the domain of your users.
  • 1 year later...
Posted

Apologies to resurface an old thread, but did anyone ever manage to get Adobe CC apps to SSO without the need for the user to first put in their email each time they logon and open up an app?

We've recently made the move from device licensing to shared device licensing, however I can see it becoming a bit of a pain for a user who just wants to open a pdf and they're then forced to sign in!

Posted
Apologies to resurface an old thread, but did anyone ever manage to get Adobe CC apps to SSO without the need for the user to first put in their email each time they logon and open up an app?

We've recently made the move from device licensing to shared device licensing, however I can see it becoming a bit of a pain for a user who just wants to open a pdf and they're then forced to sign in!

No.

The issue is with Adobe not building in pass thru authentication or a way of injecting your domain into their software.

  • Thanks 1
Posted
What about as a temp solution you set the browser as the default pdf app?

 

Thanks, this is what we've done, however it's just not as nice and as easy for our users :)

  • 3 years later...
Posted
Can you force Creative cloud auth to the browser. Users still need to enter the domain of their UPN or their UPN but if Edge/Chrome is setup for SSO it might take some pain away.
  • 2 months later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...