| name | adobe-enterprise-rbac |
| description | Configure Adobe enterprise identity with Admin Console SCIM provisioning,
User Management API, product profile-based RBAC, and Federated ID
with Azure AD or Google Workspace.
Trigger with phrases like "adobe SSO", "adobe RBAC",
"adobe enterprise", "adobe roles", "adobe SCIM", "adobe user management".
|
| allowed-tools | Read, Write, Edit |
| version | 1.6.0 |
| license | MIT |
| author | Jeremy Longshore <jeremy@intentsolutions.io> |
| tags | ["saas","design","adobe"] |
| compatibility | Designed for Claude Code |
Adobe Enterprise RBAC
Overview
Configure enterprise-grade access control for Adobe integrations using Admin Console product profiles, User Management API (UMAPI) for programmatic user provisioning, and SCIM-based identity sync with Azure AD or Google Workspace.
Prerequisites
- Adobe Enterprise or Teams subscription
- Adobe Admin Console system administrator access
- Identity Provider (Azure AD, Google Workspace, or Okta) for SSO
- Understanding of SCIM 2.0 protocol
Instructions
Step 1: Set Up Federated Identity in Admin Console
- Go to https://adminconsole.adobe.com > Settings > Identity
- Create a Federated ID directory
- Configure SSO:
- Azure AD: Admin Console > Add Azure Sync > Follow SCIM setup
- Google Workspace: Admin Console > Add Google Sync > SCIM provisioning
- Generic SAML: Upload IdP metadata XML
Adobe SP Entity ID: https://federatedid-na1.services.adobe.com/federated/saml/metadata
ACS URL: https://federatedid-na1.services.adobe.com/federated/saml/SSO
Name ID Format: urn:oasis:names:tc:SAML:2.0:nameid-format:emailAddress
Step 2: Define Product Profiles (Adobe's RBAC Mechanism)
Product Profiles in Admin Console are Adobe's native RBAC system. Create profiles that map to your application roles:
| Profile Name | Adobe APIs Granted | Application Role |
|---|
API-Developers | Firefly, PDF Services, Photoshop | Full API access |
API-Viewers | PDF Services (read-only) | Report viewers |
API-Automation | PDF Services, Document Generation | CI/CD service accounts |
API-Admin | All APIs + Admin Console | Platform administrators |
Step 3: Programmatic User Management via UMAPI
= ;
{
: ;
: ;
: ;
: ;
}
(): <> {
token = ();
response = (, {
: ,
: {
: ,
: process..!,
: ,
},
: .([{
: user.,
: ,
: [
{
: {
: user.,
: user.,
: user.,
: user.,
},
},
{
: {
: [productProfile],
},
},
],
}]),
});
(!response.) ();
result = response.();
.(, result);
}
(): <> {
token = ();
response = (, {
: ,
: {
: ,
: process..!,
: ,
},
: .([{
: email,
: ,
: [{
: {
: [productProfile],
},
}],
}]),
});
(!response.) ();
}