AEM Admin Console: Users appear directly assigned to product profile when using group-based access
This article clarifies why users who are assigned to product profiles through synced user groups appear as directly assigned in the Adobe Admin Console, and explains how to interpret assignment paths.
Description description
Environment
- Adobe Experience Manager (AEM) Brand Portal (all versions)
Symptoms
- Users are managed in the Adobe Admin Console via user groups synced from an external directory, such as Azure Active Directory.
- A user group is assigned to a product profile.
- Some users appear in the Users tab of the product profile as if they are directly assigned, even though they are members of the synced user group.
- The User Groups tab correctly shows the group assigned to the product profile.
- On the user’s details page, access is shown as *Assigned by
[user group]*and not as a direct assignment. - No errors or stack traces are present; the concern is about UI representation and access path clarity.
Cause
The Admin Console’s Users tab for a product profile shows a flattened list of all users with access, whether assigned directly or via group. This can give the impression of direct assignment, but the authoritative assignment path is shown in the user’s details. There is no double assignment or licensing impact.
Resolution resolution
Follow the steps below to resolve the issue or clarify assignment paths:
- Open the Adobe Admin Console and navigate to the relevant product profile.
- Review the Users tab. This tab displays a flattened membership list, showing all users who have access to the profile, regardless of whether access is direct or via a user group.
- Review the User Groups tab. This tab lists all user groups assigned to the product profile.
- For any user in question, click on their name to open the User Details page.
- Under Products, check the assignment path. If it states Assigned by
[user group], the user is inheriting access via group membership. There will be no separate line for Assigned directly unless a direct assignment exists. - No action is required if the user is only inheriting access via the group.
Backend licensing and seat consumption are calculated correctly: each user consumes only one seat per product/profile, regardless of assignment path.
recommendation-more-help
experience-cloud-kcs-help-kbarticles