Skip to main content
Participant
December 10, 2024
Answered

Support Conditional Access for SSO authentication from the default login

  • December 10, 2024
  • 8 replies
  • 1556 views

Our company is implementing Conditional Access with our rollout of Windows 11.  We have found that the Creative Cloud Desktop application does not support logging in to the user's Adobe ID with Single Sign On when Conditional Access is enabled.  The issue seems to be that the Device ID is not passed during the authenticaiton attempt, so Conditional Access does not trust the device, even though the device the user is attempting to login from is a trusted device. 

 

Adobe's workaround is to use Sign In using your browser.  This method works, because the browser login does pass the Device ID correctly.  But the issue with this workaround is that SIgn In using your browser is hidden in the Help menu, not in a place where it is visible to the user. 

 

We ask that Adobe improve the login experience so that the default login form passes the Device ID correctly and otherwise conforms with Micorosoft Kerberos to support logging in via SSO. 

 

Failing that, can you at least make the Sign in using your browser option available on the welcome form, rather than hiding it in the Help menu?  

 

Lastly, please make the Sign in using browser method available through Adobe Captivate.  Our Captivate users will need to have Creative Cloud Desktop installed alongside Captivate, and use it to authenticate their Adobe ID, which previously they were able to log in through Captivate without using Creative Cloud Desktop.

Correct answer AnkitVerma

Hi ​@Kindhearted_image0733

Thank you for following up, and you are right to point that out. When the Creative Cloud Desktop app requires sign-in before anything else, the "Sign in using your browser" option in the Help menu is effectively out of reach, so it only helps users who have already authenticated at least once. It does not help a fresh install sitting at the sign-in screen.

The reliable way to resolve this is to handle authentication at the deployment level, before the user ever reaches that screen. If you deploy Creative Cloud through managed packages, you can create the package from the Adobe Admin Console with the browser-based authentication option selected. When a package built this way is deployed, sign-in opens in the system default browser rather than the built-in form, so the device identity is passed through to your identity provider for the Conditional Access check and users are not left stuck at the blocked default screen.

You can create the managed package here:
https://adobe.ly/46oRO3W

The Conditional Access scenario and this browser-based authentication approach are documented here, under the Conditional Access section:
https://adobe.ly/3UhKlRz

For machines that are already deployed and currently locked out, the path forward is to repackage with that option enabled and redeploy, rather than trying to reach the Help menu on the affected device. If you can share your Creative Cloud Desktop version, your identity provider (for example Microsoft Entra or Okta), and how you are currently deploying, I would be glad to look into the specifics with you.

Regards,
^AV

8 replies

Participant
August 26, 2026

The help menu on creative cloud is not available, because the application forces you to sign in FIRST. 

AnkitVermaCommunity ManagerCorrect answer
Community Manager
August 26, 2026

Hi ​@Kindhearted_image0733

Thank you for following up, and you are right to point that out. When the Creative Cloud Desktop app requires sign-in before anything else, the "Sign in using your browser" option in the Help menu is effectively out of reach, so it only helps users who have already authenticated at least once. It does not help a fresh install sitting at the sign-in screen.

The reliable way to resolve this is to handle authentication at the deployment level, before the user ever reaches that screen. If you deploy Creative Cloud through managed packages, you can create the package from the Adobe Admin Console with the browser-based authentication option selected. When a package built this way is deployed, sign-in opens in the system default browser rather than the built-in form, so the device identity is passed through to your identity provider for the Conditional Access check and users are not left stuck at the blocked default screen.

You can create the managed package here:
https://adobe.ly/46oRO3W

The Conditional Access scenario and this browser-based authentication approach are documented here, under the Conditional Access section:
https://adobe.ly/3UhKlRz

For machines that are already deployed and currently locked out, the path forward is to repackage with that option enabled and redeploy, rather than trying to reach the Help menu on the affected device. If you can share your Creative Cloud Desktop version, your identity provider (for example Microsoft Entra or Okta), and how you are currently deploying, I would be glad to look into the specifics with you.

Regards,
^AV

jane-e
Community Expert
Community Expert
February 14, 2025

@christopher5E41 

 

I've moved your post from Creative Cloud Desktop to the Enterprise and Teams forum.

 

I'm not sure, but you may need to ask the Captivate part in the Captivate forum:

https://community.adobe.com/t5/captivate/ct-p/ct-captivate

 

Jane

 

Legend
February 14, 2025

Hi @christopher5E41 ,

 

Thank you for reaching out, and I appreciate your patience in awaiting a response. Upon review, I see that your Adobe ID is associated with an active enterprise plan.

It sounds like you are encountering an issue where the default login method in Creative Cloud Desktop does not pass the Device ID during authentication. As a result, Conditional Access policies on Windows 11 do not recognize the device as trusted, leading to authentication failures. While the “Sign in using your browser” option serves as a workaround, we understand that its current placement in the Help menu may not be ideal.

To formally submit this feedback for consideration, I recommend using the Wishform: https://adobe.ly/3EATFrH

For further assistance, you can also contact Adobe Enterprise Support here: https://adobe.ly/40RbEBC

Please let me know if you need any additional guidance.

Regards,
^AN

Participant
August 25, 2026

yeah, well it’s still not fixed