Skip to main content
Participant
July 18, 2025
Answered

Federated ID in single tenant for two separate subscriptions

  • July 18, 2025
  • 1 reply
  • 248 views

Hi - my client is the parent organisation for multiple separate business entities and they maintain a single M365 tenant to host these entities.

Two of these have their own separate Adobe subscriptions (different org name/contract number/admin console etc).

They currently just use Adobe IDs.

Is it going to be possible to establish Entra federation (SSO etc) for both these entities and keep them separate?

Rgds,

Will

Correct answer Anshul_Nautiyal

Hi @excited_developer52342,

 

Thanks for reaching out. You can have two separate Adobe Admin Consoles (with two subscriptions) both using Single Sign-On (SSO) with the same Microsoft Entra ID (Azure AD) tenant, but there are important considerations to keep in mind.

Only one Adobe Admin Console can claim and configure SSO for a given domain. This console will be responsible for setting up the Azure-based SSO directory and verifying the domain ownership.

If a second Adobe Admin Console needs to use the same domain, it cannot configure SSO independently. Instead, it must establish a Directory Trust with the first console to utilize the same authentication setup.

 

Additionally, please note that in order to use Directory Trust and SSO, users must be provisioned as Federated IDs within the Adobe Admin Console. Based on our check, the Adobe ID used to post this query is associated with a Teams license. Please be aware that SSO functionality is only available under enterprise contracts.

Check out the following documentation for your reference: 

https://adobe.ly/3UlIEPC

https://adobe.ly/4m6G9wF

 

Hope this helps. Let us know if you need further assistance.

Regards,
^AN

1 reply

Anshul_NautiyalCommunity ManagerCorrect answer
Community Manager
July 18, 2025

Hi @excited_developer52342,

 

Thanks for reaching out. You can have two separate Adobe Admin Consoles (with two subscriptions) both using Single Sign-On (SSO) with the same Microsoft Entra ID (Azure AD) tenant, but there are important considerations to keep in mind.

Only one Adobe Admin Console can claim and configure SSO for a given domain. This console will be responsible for setting up the Azure-based SSO directory and verifying the domain ownership.

If a second Adobe Admin Console needs to use the same domain, it cannot configure SSO independently. Instead, it must establish a Directory Trust with the first console to utilize the same authentication setup.

 

Additionally, please note that in order to use Directory Trust and SSO, users must be provisioned as Federated IDs within the Adobe Admin Console. Based on our check, the Adobe ID used to post this query is associated with a Teams license. Please be aware that SSO functionality is only available under enterprise contracts.

Check out the following documentation for your reference: 

https://adobe.ly/3UlIEPC

https://adobe.ly/4m6G9wF

 

Hope this helps. Let us know if you need further assistance.

Regards,
^AN