Skip to main content
Participant
April 18, 2025
Answered

Azure AD SSO, Azure Sync, Automatic Account Creation

  • April 18, 2025
  • 1 reply
  • 1164 views

Our goal: We would like to enable SSO with our Azure AD and then sync users and groups to the Adobe console so that we can automatically assign licenes based on group membership.

 

A couple question that I have as I have tried to walk through the documentation to setup the SSO and Sync:

 

  1. During the process of setting up SSO using OIDC, it asks about the "Automatic account creation". Default is enabled. Should this be disabled if we are planning on setting up sync with Azure AD or do they have seperate functions?
  2. During the process of setting up SSO using OIDC, it creates an Enterprise Application in Azure. When setting up the sync (SCIM), should I use this same Enterprise Application provisiong section or should I create a seperate one to use just for the SCIM sync?

 

Thanks in advance.

Correct answer Anshul_Nautiyal

Hi @michaelm12944181,

 

Thank you for reaching out. Based on your query, it seems that you are looking to enable SSO with Azure AD and sync users and groups to the Adobe Admin Console for automatic license assignment based on group membership. Please confirm if this is the case, and I will be happy to assist you further.

To address your question regarding "Automatic Account Creation" during the OIDC SSO setup with Azure Sync (SCIM):

It is recommended to keep "Automatic Account Creation" enabled. Here's why:

  • SCIM provisioning automatically creates and manages users and groups in the Adobe Admin Console based on their membership in Azure Active Directory.

  • OIDC SSO allows users to authenticate and sign in. If a user attempts to log in via SSO before they have been provisioned by SCIM, Automatic Account Creation ensures their account is created on the spot.

  • This serves as a fallback mechanism for users who may try to log in before SCIM has completed syncing their information, preventing login errors or delays in access.

  • Once the user is provisioned via SCIM, their account will be managed by Azure Sync, and automatic account creation will no longer apply. This ensures no conflict between the two systems.

Regarding the setup of SCIM: If you’ve already set up Azure AD SSO with OpenID Connect (OIDC), you should create a separate Adobe Identity Management application in Azure AD to configure the directory sync. This ensures the proper setup for SCIM. For more details, please refer to the "Notes prior to sync configuration" section in the following documentation: Add Azure Sync.

 

If you have any more questions or need further assistance during the setup process, please feel free to let us know. We are happy to help.

Regards,
^AN

1 reply

Anshul_NautiyalCommunity ManagerCorrect answer
Community Manager
April 18, 2025

Hi @michaelm12944181,

 

Thank you for reaching out. Based on your query, it seems that you are looking to enable SSO with Azure AD and sync users and groups to the Adobe Admin Console for automatic license assignment based on group membership. Please confirm if this is the case, and I will be happy to assist you further.

To address your question regarding "Automatic Account Creation" during the OIDC SSO setup with Azure Sync (SCIM):

It is recommended to keep "Automatic Account Creation" enabled. Here's why:

  • SCIM provisioning automatically creates and manages users and groups in the Adobe Admin Console based on their membership in Azure Active Directory.

  • OIDC SSO allows users to authenticate and sign in. If a user attempts to log in via SSO before they have been provisioned by SCIM, Automatic Account Creation ensures their account is created on the spot.

  • This serves as a fallback mechanism for users who may try to log in before SCIM has completed syncing their information, preventing login errors or delays in access.

  • Once the user is provisioned via SCIM, their account will be managed by Azure Sync, and automatic account creation will no longer apply. This ensures no conflict between the two systems.

Regarding the setup of SCIM: If you’ve already set up Azure AD SSO with OpenID Connect (OIDC), you should create a separate Adobe Identity Management application in Azure AD to configure the directory sync. This ensures the proper setup for SCIM. For more details, please refer to the "Notes prior to sync configuration" section in the following documentation: Add Azure Sync.

 

If you have any more questions or need further assistance during the setup process, please feel free to let us know. We are happy to help.

Regards,
^AN

Participant
April 19, 2025

Thank you for your response. That is exactly what I needed to know. I missed that bullet point in the "Notes prior to sync configuration" section of that documentaion page.

 

Thanks for your help!