Jump to content

Recommended Posts

Posted

Got this email from adobe today. It seems to be suggesting that with an A1 edu license we'll no longer be able to sync all user accounts?

 

 

Might also explain some recent problems with satchel one sso.

 

 

 

 

Dear valued Adobe customer,

 

Your organization configured Azure Sync on the Adobe Admin Console between July 31, 2019 – November 8, 2020, which now requires upgrading to the newest version before October 15, 2021.

 

Adobe has upgraded the Azure Sync experience to enhance security and provide additional protections to customers using this sync option. The previous version requires permission to read your organization’s full Azure Directory to sync users to the Adobe Admin Console. This version is no longer supported, requiring an update to the next version, Azure Sync with SCIM.

 

What is Azure Sync with SCIM?

 

The System for Cross-domain Identity Management, or SCIM, is an open standard protocol designed to facilitate secure, automated exchange of user identity data between your organization’s cloud apps and service providers.

What are the key changes from the previous version of Azure Sync?

 

• Your organization is no longer required to provide read access to your Azure Directory, enabling a more secure integration based on industry standard.

• You can now add Azure Sync to an existing federated directory established with Microsoft Azure or any other identity provider (IdP) for automated syncing.

• Attribute Mapping is now supported, allowing admins to map specific fields from Azure AD to the email and username fields within the Adobe Admin Console user profile for SSO login.

 

For organizations with a Microsoft Azure Subscription

 

Coinciding with the Azure Sync with SCIM release, Microsoft is changing the features within their Azure Active Directory subscription tiers.

Organizations must have a Premium (P1 or P2) or Microsoft 365 (E3 or A3) subscription with Azure Active Directory to leverage group-based assignment capabilities which allows an administrator to choose specific groups and users as the only objects to be synced to the Adobe Admin Console.

Organizations without these subscription levels can only choose to sync individual users (but not groups), or all users and groups in the directory to the Adobe Admin Console. Read more about Azure Active Directory subscription plans.

What are my options to maintain group sync capabilities?

 

Check your Microsoft Azure subscription to confirm which level your organization has and speak with your Microsoft representative if you have questions about your current Microsoft subscription.

 

How do I get started?

 

It is required to either upgrade to Azure Sync with SCIM or move off the Azure Sync integration from your organization before October 15, 2021. Get started by following these steps in the Adobe Admin Console.

Posted
Yep also had this email - thankfully we have P1 but can see this causing some school a major headache!

 

We have 1500 pupils and 100 teachers :-(

Posted
Does anyone know for sure if you need a P1 license to be able to exclude the school IP range from MFA?

 

For O365? Yes, but don't exclude your IP - MFA protects you just as much on site as it does off.

  • Thanks 1
Posted
Thanks for confirming. I haven't done much research yet to be totally honest but was thinking having MFA enabled in school for teachers would have been a real nightmare. At the moment, teachers are logging on to different computers all day. How are most schools doin this on prem?
Posted
Thanks for confirming. I haven't done much research yet to be totally honest but was thinking having MFA enabled in school for teachers would have been a real nightmare. At the moment, teachers are logging on to different computers all day. How are most schools doin this on prem?

 

It’s not the issue you think it is. We’ve had zero complaints.

Posted
It’s not the issue you think it is. We’ve had zero complaints.

 

I'm interested in how you are doing this. Are staff using their personal mobile or have you deployed a browser app like authenticator.cc ?

 

Many Thanks

Posted
I'm interested in how you are doing this. Are staff using their personal mobile or have you deployed a browser app like authenticator.cc ?

 

Many Thanks

 

They're all using their personal mobile.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...