Adobe Creative Cloud Enterprise Integration
Adobe Creative Cloud Enterprise Integration
Scimify enables SCIM provisioning for Adobe Creative Cloud Enterprise, syncing users and groups through Adobe’s User Management API (UMAPI).
Overview
This integration provisions users and user groups in Adobe Creative Cloud Enterprise via SCIM. An Adobe Enterprise organization and an OAuth Server-to-Server credential with the User Management API are required.
Prerequisites
- An Adobe Enterprise organization
- System Administrator access in Adobe Admin Console
- Access to Adobe Developer Console
- Claimed domains for Federated ID or Enterprise ID users (as applicable)
Configuration Steps
1. Create a Project in Adobe Developer Console
- Log into Adobe Developer Console as a System Admin
- Create a new project (or select an existing one)
- Add the User Management API to the project
2. Create OAuth Server-to-Server Credentials
- In your project, create an OAuth Server-to-Server credential (JWT / Service Account credentials are deprecated and should not be used)
- Copy the following values:
- Client ID
- Client Secret
- Organization ID (typically ends with
@AdobeOrg)
3. Configure the Integration in Scimify
- Navigate to the Integrations page in your Scimify admin console
- Create a new Adobe Creative Cloud Enterprise integration instance
- Enter the following configuration:
- OAuth Client ID: Client ID from Step 2
- OAuth Client Secret: Client Secret from Step 2
- Organization ID: Organization ID from Step 2
- Identity Type: How new users are created in Adobe
- Federated ID (default) — recommended for most IdP-backed enterprises
- Enterprise ID — Adobe-hosted enterprise identities
- Adobe ID — personal Adobe IDs added to your organization
- Default Country (Optional): ISO country code used when creating users (default:
US) - Group Description (Optional): Custom description for created user groups (default:
Created via Scimify for tenant {tenant_id})
4. Configure SCIM in your IdP or IGA
Follow the SCIM Configuration guide to connect Okta or Lumos to your Scimify Adobe Creative Cloud instance, then assign users and groups as needed.
How It Works
- When users are provisioned from your IdP, Scimify creates corresponding Adobe users using the configured identity type
- SCIM groups map to Adobe user groups by name (not product profiles or admin groups)
- Group membership uses user email addresses
- User and group renames, membership changes, and removals are pushed to Adobe via UMAPI action commands
License management via group push
Scimify does not assign Adobe product licenses directly. Instead, use group push and map licenses in Adobe Admin Console:
- Push groups from your IdP through Scimify so the corresponding Adobe user groups exist
- In Adobe Admin Console, assign product profiles (licenses) to those user groups
- When Scimify adds users to a group, they inherit that group’s product-profile entitlements (subject to available seats)
This lets you manage who gets Creative Cloud (and other Adobe) access from your IdP group membership, while product profiles remain configured in Adobe.
Important Notes
- Federated ID and Enterprise ID users require domains claimed in Adobe Admin Console
- Scimify manages user groups and membership only; create and attach product profiles in Adobe Admin Console
- Ensure product profiles are linked to the pushed groups before expecting licenses to apply to members
- Adobe UMAPI enforces rate limits; large syncs may take longer and will retry when throttled
- Use OAuth Server-to-Server credentials only — technical account / JWT setup is not required
Need Help?
If you encounter any issues during configuration, please contact support@veraproof.io for assistance.