Copy link to clipboard
Copied
I’m trying to enable Microsoft Defender for Cloud session policies for the acrobat.adobe.com web app. (as per here https://learn.microsoft.com/en-us/defender-cloud-apps/session-policy-aad). Session policies will provide functionality to control document upload and download from the acrobat.adobe.com web app. With Microsoft Defender for Cloud session policies, the web app must be onboarded to Defender for Cloud for conditional access control. This would then automatically redirect the application through the MCAS proxy, when SAML authentication is completed. For example:
But this does not work. SAML Authentication itself is working, but with the redirect to https://auth.services.adobe.com.mcas.ms, Adobe generates an error: “Could not log you in. This might be a sign of an IDP initiated login, which we don't support.”
Microsoft Defender for Cloud has functionality to specify the specific login URL to redirect to after successful SAML authentication, but it is not clear if acrobat.adobe.com has such a deeplink URL to facilitate IDP initiated login. There is a similar Adobe Acrobat Sign article explaining how this can be done for Adobe Acrobat Sign (see https://helpx.adobe.com/sign/using/adobesign-enable-sso-when-auth-by-idp.html?linkId=100000380207640) but could not find anything similar for acrobat.adobe.com.
Would appreciate further information on how this can be achieved.
Copy link to clipboard
Copied
Hello @Defender for Cloud
I hope you are doing well, and thank you for reaching out.
Currently, Microsoft Defender for Cloud session policies are not officially supported for 'acrobat.adobe.com' because the Acrobat web does not support IDP-initiated SAML login flows. As you correctly observed, Acrobat uses a service-initiated (SP-initiated) SAML authentication process, which means that authentication must begin from the Acrobat web app itself.
Adobe supports SSO via SAML through Federated IDs, and you can configure this using the Adobe Admin Console. However, this setup is designed for SP-initiated logins, where the user starts authentication from the Adobe service, not from the identity provider or a proxy like MCAS. See this article for more information: Set up identity and Single Sign-On. You can also post your question to the Enterprise Community team and see if the experts can assist you with any workaround: Enterprise & Teams.
You can also use the Adobe Wish form to raise a feature request with the product team.
Thanks,
Anand Sri.
Find more inspiration, events, and resources on the new Adobe Community
Explore Now