Exit
  • Global community
    • Language:
      • Deutsch
      • English
      • Español
      • Français
      • Português
  • 日本語コミュニティ
  • 한국 커뮤니티
0

Adobe Acrobat online and Microsoft Defender for Cloud session policies

New Here ,
Oct 07, 2025 Oct 07, 2025

I’m trying to enable Microsoft Defender for Cloud session policies for the acrobat.adobe.com web app. (as per here https://learn.microsoft.com/en-us/defender-cloud-apps/session-policy-aad). Session policies will provide functionality to control document upload and download from the acrobat.adobe.com web app.  With Microsoft Defender for Cloud session policies, the web app must be onboarded to Defender for Cloud for conditional access control. This would then automatically redirect the application through the MCAS proxy, when SAML authentication is completed. For example:

  • Go to acrobat.adobe.com and sign-in
  • SAML sign-in will redirect to the Microsoft sign-in page where the user can sign in with Azure credentials.
  • After successful authentication, the application is redirected to https://auth.services.adobe.com.mcas.ms/ and then to acrobat.adobe.com.mcas.ms.
  • Microsoft Defender for Cloud session policies would then be applied through the mcas.ms proxy.

 

But this does not work. SAML Authentication itself is working, but with the redirect to https://auth.services.adobe.com.mcas.ms, Adobe generates an error: “Could not log you in. This might be a sign of an IDP initiated login, which we don't support.”

DefenderforCloud_0-1759882752721.png

 

Microsoft Defender for Cloud has functionality to specify the specific login URL to redirect to after successful SAML authentication, but it is not clear if acrobat.adobe.com has such a deeplink URL to facilitate IDP initiated login. There is a similar Adobe Acrobat Sign article explaining how this can be done for Adobe Acrobat Sign (see https://helpx.adobe.com/sign/using/adobesign-enable-sso-when-auth-by-idp.html?linkId=100000380207640) but could not find anything similar for acrobat.adobe.com.

 

Would appreciate further information on how this can be achieved.

85
Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Adobe Employee ,
Oct 08, 2025 Oct 08, 2025
LATEST

Hello @Defender for Cloud

 

I hope you are doing well, and thank you for reaching out.

 

Currently, Microsoft Defender for Cloud session policies are not officially supported for 'acrobat.adobe.com' because the Acrobat web does not support IDP-initiated SAML login flows. As you correctly observed, Acrobat uses a service-initiated (SP-initiated) SAML authentication process, which means that authentication must begin from the Acrobat web app itself.

 

Adobe supports SSO via SAML through Federated IDs, and you can configure this using the Adobe Admin Console. However, this setup is designed for SP-initiated logins, where the user starts authentication from the Adobe service, not from the identity provider or a proxy like MCAS. See this article for more information: Set up identity and Single Sign-On. You can also post your question to the Enterprise Community team and see if the experts can assist you with any workaround: Enterprise & Teams.

 

You can also use the Adobe Wish form to raise a feature request with the product team.

 

Thanks,

Anand Sri.

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines