Short answer: Go to account.adobe.com → Account and security → Sign-in and security, and enable two-step verification. Choose the authenticator app option rather than SMS, scan the QR code, confirm with the six-digit code, and save the recovery codes. If your Adobe ID is a work account managed by your employer, 2FA is handled by their identity provider instead.
What is actually at stake
An Adobe account is not just a subscription. It holds:
- Cloud files and libraries — active client work, brand assets, shared libraries.
- Adobe Stock licences and download credits, which have direct resale value.
- A payment method on an expensive recurring subscription.
- Behance and portfolio profiles tied to the same identity.
- Document signing through Acrobat Sign — which means the ability to sign things as you.
That last one deserves attention. If you use Acrobat Sign for contracts, an account takeover is not just inconvenient; it is someone able to execute documents in your name.
The common attack is unglamorous: a password reused from an old design forum breach, or a phishing email about a failed subscription payment.
First: is it a personal or work Adobe ID?
Adobe has three account types, and it matters:
- Personal Adobe ID — you control it, and the steps below apply.
- Business ID — created by an organisation, which may enforce its own policies.
- Federated ID — authentication is delegated to your employer’s identity provider, so Adobe’s own 2FA setting will not appear. Security lives upstream — see what is single sign-on.
If the two-step verification option is missing, you almost certainly have a Federated ID. Speak to your IT team rather than assuming you are unprotected.
Step 1: Enable two-step verification
- Go to account.adobe.com and sign in.
- Open Account and security → Sign-in and security.
- Find Two-step verification and turn it on.
- Confirm your password.
Step 2: Choose the app over SMS
Adobe typically offers an authenticator app, SMS, or email as verification methods.
Pick the authenticator app. Codes are generated offline on your device, with nothing travelling through the mobile network where a SIM swap could intercept them. The full comparison is in SMS 2FA vs authenticator apps.
Adobe shows a QR code with a text key beneath it. Scan it with Google Authenticator, Aegis, 2FAS, Microsoft Authenticator or a password manager — see what is an authenticator app if this is new, or manual key entry if the code will not scan.
Do not screenshot the QR code. Designers screen-share and record constantly — set this up with sharing off.
Step 3: Save the recovery codes
Adobe issues backup codes. Save them offline or in a password manager, not in Creative Cloud Files — the account you would be locked out of.
Adobe’s account recovery involves support and identity verification, which is slow when a client deadline is the reason you need access. See where to store backup codes safely, and enrol a second device while the QR code is on screen — the method is in how to back up your authenticator app.
Step 4: Clean up the account
Still under Account and security:
- Devices and active sessions — sign out anything unfamiliar or long gone. Creative Cloud allows a limited number of activations, so old machines are worth removing anyway.
- Connected accounts — Google, Facebook and Apple sign-in links. If any of these can authenticate as you, that account’s security is now your Adobe security. Remove links you do not use.
- Linked apps and services — third-party integrations with access to your libraries.
- Email address — current, and protected with its own strong 2FA (Google, Microsoft).
If you work with clients or an agency, check who has access to shared libraries and team folders too — that is the equivalent of a shared login, and it needs the same offboarding discipline described in 2FA for freelancers. If you take work through marketplaces, our guide to 2FA on Upwork and Fiverr covers those accounts.
The phishing designers actually get
- “Your subscription payment failed” — the most common, and effective because Adobe subscriptions genuinely do fail on expired cards.
- Fake font or plugin installers, particularly for cracked versions of Adobe software. These are a leading source of infostealer malware, which takes session cookies and bypasses 2FA entirely — see session hijacking.
- Client “brief” files from unvetted contacts that are actually executables.
- Fake Acrobat Sign requests — a document notification leading to a credential harvester.
The rule that covers all of them: never sign in from a link in an email. Type account.adobe.com yourself.
Frequently asked questions
I can’t find two-step verification. Why?
Most likely you have a Federated ID managed by an employer, so authentication happens at their identity provider. Alternatively you sign in with Google or Apple, in which case secure that account instead.
Which authenticator app works with Adobe?
Any standard TOTP app. Adobe uses the normal algorithm — see how TOTP codes work.
Will I need a code every time I open Photoshop?
No. Your installed apps stay signed in. Codes are requested for new sign-ins and account changes.
Why is my code rejected?
Usually clock drift on your phone. Turn on automatic network time. More: why 2FA codes get rejected.
What if I lose my phone?
Use a recovery code, or Adobe support with identity verification. See recovering accounts after losing your 2FA phone.
Does Adobe support passkeys?
Adobe has been rolling out passwordless and passkey options across its sign-in flows. If you see the option in your account, take it — passkeys cannot be phished, which matters given how much Adobe-themed phishing circulates. See passkeys vs 2FA.
The bottom line
Three minutes for the app and the recovery codes, five more for old devices and connected sign-in methods. Then be careful with cracked plugins and unexpected “brief” files — because for designers, the compromise usually arrives disguised as work rather than as an attack.
Securing the rest of your creative stack? See Canva and 2FA for freelancers. Students and teachers may also want our guide to Figma’s free education plan.