> ## Documentation Index
> Fetch the complete documentation index at: https://knowledge.woho.solutions/llms.txt
> Use this file to discover all available pages before exploring further.

# Identity and Single Sign-On

> Choose the right Adobe account type, verify your organisation's domain, and connect Microsoft Entra ID or Google Workspace for single sign-on.

Identity settings control **how your users sign in** to Adobe and **who owns their accounts**. Getting this right early makes onboarding, offboarding, and security much simpler. This is usually a one-time setup.

<Info>
  Identity and single sign-on (SSO) setup involves DNS changes and your identity provider. **WOHO includes this as part of Adobe deployment**, so you can hand it over to us. The steps below explain what's involved.
</Info>

## Choose an account type

| Account type               | Who owns the account                                         | How users sign in                             | Best for                                              |
| -------------------------- | ------------------------------------------------------------ | --------------------------------------------- | ----------------------------------------------------- |
| **Adobe ID / Business ID** | The user, with business content managed by your organisation | Email and an Adobe password                   | Small teams wanting the quickest setup                |
| **Enterprise ID**          | Your organisation                                            | Email on your domain and an Adobe password    | Organisations wanting control without SSO             |
| **Federated ID**           | Your organisation                                            | Single sign-on through your identity provider | Organisations using Microsoft 365 or Google Workspace |

For most WOHO customers already on Microsoft 365, **Federated ID with Microsoft Entra ID** is the recommended choice. Users sign in to Adobe with the same work account they use for Outlook and Teams, and leavers lose Adobe access automatically when their Microsoft account is disabled.

## Setup overview

<Steps>
  <Step title="Create a directory">
    In the Admin Console, go to **Settings** > **Identity** > **Directories** and select **Create directory**. Give it a name, for example your company name, and choose **Federated ID** or **Enterprise ID**.
  </Step>

  <Step title="Add your domain">
    Go to **Settings** > **Identity** > **Domains** and select **Add domains**. Enter the email domain your users use, for example `yourcompany.mu`.
  </Step>

  <Step title="Verify domain ownership">
    Adobe provides a **DNS TXT record**. Add it at your domain registrar or DNS host, then return to the Admin Console and select **Verify**. DNS changes can take from a few minutes to 72 hours to take effect.
  </Step>

  <Step title="Link the domain to the directory">
    Once verified, select the domain, choose **Link to directory**, and choose the directory you created.
  </Step>

  <Step title="Connect your identity provider (Federated ID only)">
    Open the directory and choose your provider:

    * **Microsoft Azure** (Microsoft Entra ID): sign in with a Microsoft global administrator account and accept the permissions. Users and groups can then sync automatically.
    * **Google**: sign in with a Google Workspace super administrator account.
    * **Other SAML providers**: exchange metadata files between the Admin Console and your provider, such as Okta.
  </Step>

  <Step title="Test before rolling out">
    Test sign-in with one or two users before you move everyone across. Check that they can sign in to the Creative Cloud desktop app and to Acrobat.
  </Step>
</Steps>

<Note>
  **Adobe official guides:** [Set up identity with SSO](https://helpx.adobe.com/business/enterprise/identity-sso/set-up-identity/set-up-identity-with-sso.html) · [Set up domains for directory authentication](https://helpx.adobe.com/business/enterprise/directories-domains-access/directories-and-domains/add-domains-to-directories.html) · [Authenticate your users with Microsoft Entra ID](https://helpx.adobe.com/business/enterprise/identity-sso/integrate-with-microsoft-entra/sso-setup-azure.html)
</Note>

<Warning>
  Changing account types for existing users is a **migration**, not a setting. Users may need to move their files to the new account. WOHO plans these migrations with you so no work is lost. Please [contact us](/support/contact) before changing identity settings for an organisation that already has active users.
</Warning>

## Automatic user sync

With Federated ID on Microsoft Entra ID or Google Workspace, you can **sync users and groups automatically** from your identity provider, so you don't need to add users by hand in the Admin Console:

* New starters added to a synced group appear in Adobe and can receive licences automatically.
* Leavers removed from the group or disabled in your identity provider lose their Adobe access.

WOHO can configure which groups sync and map them to the right Adobe product profiles.

<Note>
  **Adobe official guide:** [Add Microsoft Entra ID Sync](https://helpx.adobe.com/business/enterprise/identity-sso/integrate-with-microsoft-entra/add-microsoft-entra-id-sync.html)
</Note>

## Related guides

<CardGroup cols={2}>
  <Card title="Add users" icon="user-plus" href="/partners/adobe/admin-console/adding-users">
    Add users manually or by CSV.
  </Card>

  <Card title="Troubleshooting" icon="wrench" href="/partners/adobe/admin-console/troubleshooting">
    Fix sign-in and domain issues.
  </Card>
</CardGroup>
