# Setting up an Amazon Connect instance

Systems: Amazon Connect Customer

For AWS or contact-center administrators building an Amazon Connect Customer instance who can create IAM resources in their AWS account.

Canonical: https://warmtransfer.net/guides/amazon-connect-instance-setup

Last verified: 2026-09-30

Amazon Connect Customer is the current name for the contact center product previously called Amazon Connect, and the name Amazon Connect now refers to a set of agentic AI solutions[^39]. Creating an instance offers 3 identity management options, and the option you choose cannot be changed after the instance is created[^31][^30].

## Before you start

The person creating the instance must have the permissions granted by the AmazonConnect_FullAccess IAM policy[^25]. The default quota is 2 Connect Customer instances per Region, adjustable at the account level[^32].

Decide the identity option first, because it cannot be changed after the instance is created[^30]. Moving an instance to a different identity management option means deleting the instance and creating a new one, which loses its configuration settings and metrics data[^29].

Connect Customer is available in US East, US West (Oregon), Africa (Cape Town), Asia Pacific (Seoul, Singapore, Sydney, Tokyo), Canada (Central), Europe (Frankfurt, London) and AWS GovCloud (US-West)[^42]. Apple Messages for Business, SMS, WhatsApp Business Messaging and push notifications integrations are not available in AWS GovCloud (US-West)[^26].

- A unique label for the instance Access URL if you choose Connect-managed or SAML identity, because it must be unique across all Connect Customer instances in all Regions[^3].
- For the directory option, an AWS Managed Microsoft Active Directory, AD Connector or Simple AD directory[^22].
- For SAML, an administrator user name that exactly matches a user name in your existing network directory[^47].
- A browser for agent testing: agents using the Contact Control Panel (CCP) with a softphone must use Chrome, Edge or Firefox and grant microphone access[^58].

See also [Amazon Connect pricing](https://warmtransfer.net/knowledge/amazon-connect-pricing).

See also [Setting up queues and routing profiles in Amazon Connect](https://warmtransfer.net/knowledge/amazon-connect-routing-profile-setup).

## What changes by situation

- How will users of the instance sign in? Store users in Connect Customer; Link to an existing Directory Service directory; SAML 2.0-based authentication using an existing identity provider.
- Which AWS Region will host the instance? A Region other than Africa (Cape Town) or AWS GovCloud (US-West), such as US West (Oregon) or Europe (London); Africa (Cape Town); AWS GovCloud (US-West).

## Step 1: Choose the Region

### Do

AWS recommends anchoring either the phone numbers or the agents in the AWS Region where they are geographically located[^33]. If both are in a different Region from the instance, WebRTC round-trip network latency is extended above 500 ms and call quality may suffer[^33]. AWS advises calculating latency in a test environment before production, using the Connect Customer Endpoint Test Utility[^23]. If you need Apple Messages for Business, SMS, WhatsApp Business Messaging or push notifications, AWS GovCloud (US-West) does not offer those integrations[^26].

### Verify

AWS recommends under 500 ms end-to-end latency for best call quality, says up to 900 ms combined network and telephony latency may be acceptable, and states that above 900 ms causes significant delay between agents and customers[^34]. Suggested check: record the latency measured from each agent location and keep it with your design notes.

## Step 2: Prepare the identity source

**Store users in Connect Customer**

### Do

Choose the left-most label of the instance Access URL now; it must be unique across all Connect Customer instances in all Regions and cannot be changed after the instance is created[^3].

### Verify

Suggested check: write down the chosen label and have a second administrator confirm the spelling before you continue.

**Link to an existing Directory Service directory**

### Do

Set up an AWS Managed Microsoft Active Directory, AD Connector or Simple AD directory[^22]. The directory must be associated with your AWS account, set up in Directory Service, and active in the same AWS Region in which you create the instance[^21]. A Directory Service directory can be associated with only 1 Connect Customer instance at a time[^20].

### Verify

Confirm the directory is active in the target Region and associated with your account[^21]. Confirm it is not already associated with another Connect Customer instance, because to reuse it you must delete the instance it is associated with[^20].

### Rollback

Suggested rollback: until you link the directory in Step 3, nothing outside the directory itself has changed. A directory cannot be unbound from a Connect Customer instance after it has been associated[^19].

**SAML 2.0-based authentication using an existing identity provider**

### Do

AWS advises configuring the SAML environment before creating the instance, and with SAML users can log in only through the link configured in the identity provider[^52]. Choose the left-most label of the Access URL; it must be unique across all Connect Customer instances in all Regions and cannot be changed after creation[^3]. Pick the administrator user name, which must exactly match a user name in your existing network directory[^47].

### Verify

Suggested check: confirm that someone who administers the identity provider is available to finish the federation setup in Step 5.

## Step 3: Create the instance: identity and administrator

**Store users in Connect Customer**

### Do

Choose Store users in Connect Customer as the identity management option[^31]. Enter the Access URL label you chose earlier[^3]. Specify the administrator with a name, password and email[^5].

### Verify

The administrator named during creation is created as a Connect Customer user account and assigned the Admin security profile[^6]. Suggested check: before you continue, confirm the identity option and administrator details shown for review match your plan.

### Rollback

Suggested rollback: before the instance is created, return to the identity page and correct it. After creation, moving to a different identity option requires deleting the instance and creating a new one[^29].

**Link to an existing Directory Service directory**

### Do

Choose Link to an existing directory and select the directory you prepared[^31]. For this option the directory name is used as the Access URL label[^3]. Enter an existing directory username as the administrator; the directory manages that user's password[^5].

### Verify

The administrator is created as a Connect Customer user account and assigned the Admin security profile[^6]. Suggested check: confirm the directory and administrator shown for review are the ones you intended.

### Rollback

A directory cannot be unbound from a Connect Customer instance after it has been associated[^19]. To use the directory with a different instance you must delete the instance it is associated with[^20].

**SAML 2.0-based authentication using an existing identity provider**

### Do

Choose SAML 2.0-based authentication[^31]. Enter the Access URL label you chose earlier[^3]. Enter an administrator name that exactly matches a user name in your network directory; there is no option to set a password for it[^47].

### Verify

User names on a SAML instance are case sensitive[^57]. Suggested check: compare the administrator name shown for review character by character with the directory entry.

### Rollback

Suggested rollback: before the instance is created, return to the identity page and correct it. After creation, moving to a different identity option requires deleting the instance and creating a new one[^29].

## Step 4: Set telephony and data storage, then create

### Do

On the Set telephony step, select Receive inbound calls and Make outbound calls as needed; the same step also offers Enable early media and multi-party calls and chats of up to 6 participants with enhanced monitoring[^60]. Review data storage: by default instance creation creates Amazon S3 buckets for call recordings, chat transcripts, exported reports, flow logs and email messages, with data encrypted using AWS KMS[^15].

### Verify

Instances using Connect-managed users or a Directory Service directory are accessed through the instance Access URL, while SAML instances are accessed through the identity provider[^2]. Suggested check: confirm the new instance is listed in the Region you chose in Step 1.

### Rollback

A deleted Connect Customer instance cannot be restored, and its settings, data, metrics and reports become inaccessible[^17]. Flow-log CloudWatch log groups must be deleted separately if no longer needed[^17]. Deleting an instance releases its claimed phone numbers back to inventory, and callers to a released number hear that it is not a working number[^18].

## Step 5: Establish administrator sign-in

**Store users in Connect Customer**

### Do

Open the instance Access URL and sign in as the administrator, because instances using Connect-managed users are accessed through the Access URL[^2].

### Verify

The administrator holds the Admin security profile[^6]. Suggested check: confirm the admin website loads and that you can open its user management pages.

**Link to an existing Directory Service directory**

### Do

Open the instance Access URL, because instances using a Directory Service directory are accessed through it[^2]. Sign in with the administrator's directory username, whose password the directory manages[^5].

### Verify

The administrator holds the Admin security profile[^6]. Suggested check: confirm the admin website loads and that you can open its user management pages.

**SAML 2.0-based authentication using an existing identity provider + A Region other than Africa (Cape Town) or AWS GovCloud (US-West), such as US West (Oregon) or Europe (London)**

### Do

Create a SAML identity provider in IAM and a single IAM role for SAML 2.0 federation whose policy allows connect:GetFederationToken for the instance, and leave the identity provider's Application Start URL blank[^50]. Set the relay state to https://{region-id}.console.aws.amazon.com/connect/federate/{instance-id}, where the instance ID is the value after /instance in the instance ARN[^54]. AWS recommends overriding the identity provider's Assertion Consumer Service URL from the global sign-in endpoint, which is hosted in US East, to https://{region-id}.signin.aws.amazon.com/saml for the instance's Region, and adding that URL to a multivalued SAML:aud condition in the role trust policy[^53].

### Verify

Connect Customer does not support service-provider-initiated SAML federation, so going to the instance directly produces a Session Expired message[^51]. Suggested check: start from the identity provider's portal as the administrator and confirm the admin website loads.

### Rollback

Suggested rollback: remove the identity provider application, the federation role and the SAML identity provider you created in this step. The instance keeps its SAML identity option either way, because that option cannot be changed after creation[^30].

**SAML 2.0-based authentication using an existing identity provider + Africa (Cape Town)**

### Do

Create a SAML identity provider in IAM and a single IAM role for SAML 2.0 federation whose policy allows connect:GetFederationToken for the instance, and leave the identity provider's Application Start URL blank[^50]. AWS documents the relay state for a commercial-Region SAML instance as https://{region-id}.console.aws.amazon.com/connect/federate/{instance-id}, where the instance ID is the value after /instance in the instance ARN[^54]. AWS recommends overriding the Assertion Consumer Service URL from the global sign-in endpoint to https://{region-id}.signin.aws.amazon.com/saml for the instance's Region, and adding that URL to a multivalued SAML:aud condition in the role trust policy[^53].

### Verify

Going to the instance directly produces a Session Expired message, because users must authenticate at the identity provider[^51]. Suggested check: start from the identity provider's portal as the administrator and confirm the admin website loads.

### Rollback

Suggested rollback: remove the identity provider application, the federation role and the SAML identity provider you created in this step. The instance keeps its SAML identity option either way, because that option cannot be changed after creation[^30].

**SAML 2.0-based authentication using an existing identity provider + AWS GovCloud (US-West)**

### Do

Create a SAML identity provider in IAM and a single IAM role for SAML 2.0 federation whose policy allows connect:GetFederationToken for the instance, and leave the identity provider's Application Start URL blank[^50]. For an AWS GovCloud instance, set the relay state to https://console.amazonaws-us-gov.com/connect/federate/{instance-id}[^49]. AWS recommends overriding the Assertion Consumer Service URL from the global sign-in endpoint, hosted in US East, to the regional sign-in endpoint for the instance's Region, and adding that URL to a multivalued SAML:aud condition in the role trust policy[^53].

### Verify

Going to the instance directly produces a Session Expired message, because users must authenticate at the identity provider[^51]. Suggested check: start from the identity provider's portal as the administrator and confirm the admin website loads.

### Rollback

Suggested rollback: remove the identity provider application, the federation role and the SAML identity provider you created in this step. The instance keeps its SAML identity option either way, because that option cannot be changed after creation[^30].

## Step 6: Claim a phone number

**A Region other than Africa (Cape Town) or AWS GovCloud (US-West), such as US West (Oregon) or Europe (London)**

### Do

As an Admin or a user with Phone numbers - Claim permission, choose Channels, Phone numbers, Claim a number, pick a toll-free or DID number (with an optional area code filter in the US), optionally attach a flow in Flow / IVR, and save[^10]. Since July 2023, claiming numbers located in countries outside the instance's AWS Region no longer requires opt-in approval; AWS provides best-practice design guidance instead[^14]. Country or region regulations often require a local office address and specific identification documents, and addresses such as PO boxes are not valid in any country[^36]. If no numbers display for a country or region, or a wanted area code or prefix is not listed, create an Account and billing support case[^12].

### Verify

You can call a newly claimed number immediately, and Connect Customer uses the default flows for that initial experience[^61]. The default quota is 10 phone numbers per instance, and the "You've reached the limit of Phone Numbers" error can appear even on a first claim and requires AWS Support to resolve[^38].

### Rollback

After you release a claimed number you cannot claim the same number again[^43]. Claiming and releasing beyond 200% of the phone number quota within a rolling 180-day cycle blocks further claims until 180 days after the oldest released number, unless you obtain a quota exception[^11].

**Africa (Cape Town)**

### Do

As an Admin or a user with Phone numbers - Claim permission, choose Channels, Phone numbers, Claim a number, pick a toll-free or DID number, optionally attach a flow in Flow / IVR, and save[^10]. The published ID requirements for ordering and porting numbers apply to all AWS Regions except Africa (Cape Town) and AWS GovCloud (US-West) unless noted otherwise per country[^37]. If no numbers display, or a wanted area code or prefix is not listed, create an Account and billing support case[^12].

### Verify

You can call a newly claimed number immediately, and Connect Customer uses the default flows for that initial experience[^61]. The "You've reached the limit of Phone Numbers" error can appear even on a first claim and requires AWS Support to resolve[^38].

### Rollback

After you release a claimed number you cannot claim the same number again[^43]. Claiming and releasing beyond 200% of the phone number quota within a rolling 180-day cycle blocks further claims unless you obtain a quota exception[^11].

**AWS GovCloud (US-West)**

### Do

As an Admin or a user with Phone numbers - Claim permission, choose Channels, Phone numbers, Claim a number, pick a toll-free or DID number, optionally attach a flow in Flow / IVR, and save[^10]. The published ID requirements for ordering and porting numbers apply to all AWS Regions except Africa (Cape Town) and AWS GovCloud (US-West) unless noted otherwise per country[^37]. If no numbers display, or a wanted area code or prefix is not listed, create an Account and billing support case[^12].

### Verify

You can call a newly claimed number immediately, and Connect Customer uses the default flows for that initial experience[^61]. The "You've reached the limit of Phone Numbers" error can appear even on a first claim and requires AWS Support to resolve[^38].

### Rollback

After you release a claimed number you cannot claim the same number again[^43]. Claiming and releasing beyond 200% of the phone number quota within a rolling 180-day cycle blocks further claims unless you obtain a quota exception[^11].

## Step 7: Create hours of operation

### Do

As an Admin or a user with Routing - Hours of operation - Create permission, choose Routing, Hours of operation, Add new set of hours, enter a name, choose a time zone and set the operational hours[^28].

### Verify

Hours of operation are specified on a queue and can be tested in flows with the Check hours of operation block to branch contacts outside hours[^27]. Suggested check: confirm the new set appears in the list of hours.

### Rollback

Suggested rollback: edit the set of hours, or select a different set on the queue.

## Step 8: Create a queue

### Do

Choose Routing, Queues, Add new queue, and set the hours of operation you created, the outbound caller ID, the maximum contacts and any quick connects[^40]. Only phone numbers claimed in or ported to the instance can be used as the outbound caller ID number, unless an external number has been activated for custom caller ID through an AWS Support case[^62].

### Verify

A new queue is automatically active[^40]. A routing profile is what links queues to agents[^45].

### Rollback

Suggested rollback: edit the queue's settings, or stop using it by removing it from routing profiles.

## Step 9: Create a routing profile

### Do

Choose Users, Routing profiles, Add routing profile, set channel availability and concurrency, add the queue you created with a channel, priority and delay, and choose a default outbound queue, whose settings such as caller ID outbound contacts respect[^46]. In the Queues section a lower priority number is handled first, and the delay is the minimum time in seconds a contact must be in the queue before it is routed to an available agent[^63].

### Verify

The channel set for a queue in the routing profile must also be enabled in the profile's Channel Settings, otherwise contacts from that channel will not be routed to agents[^44]. Suggested check: confirm that Voice is enabled in the profile and on the queue entry.

### Rollback

Each agent is assigned exactly 1 routing profile[^45]. Suggested rollback: edit the profile, or assign affected agents to a different profile.

## Step 10: Decide security profiles

### Do

Connect Customer includes 4 default security profiles: Admin, Agent (access to the CCP), CallCenterManager (user management, metrics and routing) and QualityAnalyst (metrics)[^16]. AWS advises using a default profile only if it matches what users need and otherwise creating a profile that grants only the needed permissions, and notes new permissions are added regularly[^35]. A user with Security profiles - Create permission creates one under Users, Security profiles, Add new security profile, and choosing an action automatically selects the actions it depends on, such as View when Edit is chosen[^59].

### Verify

By default, users assigned the Agent security profile can access the Contact Control Panel and make outbound calls[^8]. Suggested check: if you built a narrower agent profile, confirm it still grants panel access and outbound calling.

### Rollback

Suggested rollback: edit the profile, or assign users back to a default profile.

## Step 11: Add an agent user

**Store users in Connect Customer**

### Do

Choose Users, Add new users, enter name, email and password, and choose the routing profile you created and a security profile[^4]. Then edit the user and set Phone Type to Soft phone; for soft phone AWS recommends enabling persistent connection[^4][^7].

### Verify

Each agent is assigned exactly 1 routing profile[^45]. Suggested check: confirm the user is listed with the routing profile from Step 9.

### Rollback

Suggested rollback: edit the user's settings or remove the user.

**Link to an existing Directory Service directory**

### Do

Choose Users, Add new users, and choose the routing profile you created and a security profile[^4]. Then edit the user and set Phone Type to Soft phone; for soft phone AWS recommends enabling persistent connection[^4][^7].

### Verify

Each agent is assigned exactly 1 routing profile[^45]. Suggested check: confirm the user is listed with the routing profile from Step 9.

### Rollback

Suggested rollback: edit the user's settings or remove the user.

**SAML 2.0-based authentication using an existing identity provider**

### Do

Add the user with a user name that exactly matches the RoleSessionName attribute in your identity provider's SAML response; user names are case sensitive[^57]. SAML users have no primary email address or password, and they need a secondary email configured to receive email notifications[^56]. Edit the user afterwards and set Phone Type to Soft phone; for soft phone AWS recommends enabling persistent connection[^4][^7].

### Verify

A user with no matching account sees an Access denied message[^57]. Suggested check: have the agent sign in through the identity provider and confirm no access error appears.

### Rollback

Suggested rollback: edit the user's settings or remove the user.

## Step 12: Attach the number to a flow

### Do

Choose Channels, Phone numbers, choose the number you claimed, and select the flow in Flow / IVR; only published flows appear in that list[^24].

### Verify

To test a customised flow you assign a number to it and call that number[^61]. Suggested check: call the number from an outside phone and confirm you hear the flow you selected.

### Rollback

Suggested rollback: reselect the previously attached flow on the same number.

## Step 13: Test the agent softphone end to end

**Store users in Connect Customer**

### Do

Use Chrome, Edge or Firefox and grant the browser microphone access[^58]. Open https://{instance name}.my.connect.aws/ccp-v2/ and sign in as the agent you added[^9].

### Verify

Suggested check: set the agent to a state that receives contacts, then call the number from an outside phone. Agents have 20 seconds to accept a voice contact, after which their status becomes Missed and the contact routes to the next available agent; this window is not configurable[^1]. The default quota for concurrent active calls per instance is 10, and calls beyond it receive a reorder (fast busy) tone[^13].

**Link to an existing Directory Service directory**

### Do

Use Chrome, Edge or Firefox and grant the browser microphone access[^58]. Open https://{instance name}.my.connect.aws/ccp-v2/ and sign in as the agent you added[^9].

### Verify

Suggested check: set the agent to a state that receives contacts, then call the number from an outside phone. Agents have 20 seconds to accept a voice contact, after which their status becomes Missed and the contact routes to the next available agent[^1]. The default quota for concurrent active calls per instance is 10, and calls beyond it receive a reorder (fast busy) tone[^13].

**SAML 2.0-based authentication using an existing identity provider**

### Do

Use Chrome, Edge or Firefox and grant the browser microphone access[^58]. Sign in through the identity provider, because users must authenticate there[^51]. A URL-encoded destination parameter on the relay state URL, such as destination=%2Fccp-v2, can send users straight to the CCP if their security profile grants access to it[^48].

### Verify

Suggested check: set the agent to a state that receives contacts, then call the number from an outside phone. Agents have 20 seconds to accept a voice contact, after which their status becomes Missed and the contact routes to the next available agent[^1]. The default quota for concurrent active calls per instance is 10, and calls beyond it receive a reorder (fast busy) tone[^13]. SAML sessions expire 12 hours after login and the user is logged out even if on a call, so agents working longer must log out of Connect Customer and the identity provider and log in again before expiry[^55].

## Applicability

Applies to: Amazon Web Services Amazon Connect Customer and Amazon Web Services Amazon Connect. Deployments: multi-tenant. Sources checked 2026-10-01. Apple Messages for Business, SMS, WhatsApp Business Messaging and push notifications integrations are not available in AWS GovCloud (US-West)[^26]. The published ID requirements for ordering and porting numbers exclude Africa (Cape Town) and AWS GovCloud (US-West) unless noted otherwise per country[^37]. The removal of opt-in approval for numbers outside the instance's Region applies from July 2023 onward[^14].

## What remains uncertain

Whether an existing instance can be moved to a different AWS Region is not covered by the sources below. The exact Assertion Consumer Service URL for an AWS GovCloud (US-West) instance is not covered by the sources below. Which identity management options and other features are supported in AWS GovCloud (US-West), beyond the unavailable messaging integrations, is not covered by the sources below. Which countries' numbers can actually be claimed in Africa (Cape Town) and AWS GovCloud (US-West) is not covered by the sources below. Whether the quotas applied to a given account match the documented defaults is not covered by the sources below.

## Sources

[^1]: Agents have 20 seconds to accept a voice or chat contact (30 seconds for a task), after which their status becomes Missed and the contact routes to the next available agent; this window is not configurable. Source: [Configure agent settings in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/configure-agents.html), Note above 'To configure agent settings'. Checked 2026-09-30.
[^2]: After creation, instances using Connect-managed users or a Directory Service directory are accessed through the instance Access URL, while SAML instances are accessed through the identity provider. Source: [Create a Connect Customer instance](https://docs.aws.amazon.com/connect/latest/adminguide/amazon-connect-instances.html), Step 5: Review and create, item 5 second paragraph. Checked 2026-09-30.
[^3]: For Connect-managed or SAML identity you supply the left-most label of the instance Access URL; it must be unique across all Connect Customer instances in all Regions and cannot be changed after the instance is created, while for the directory option the directory name is used as that label. Source: [Create a Connect Customer instance](https://docs.aws.amazon.com/connect/latest/adminguide/amazon-connect-instances.html), Step 1: Set identity, items 4 and 5. Checked 2026-09-30.
[^4]: A user is added under Users, Add new users, entering name, email and password and choosing a routing profile and security profile; phone type, auto-accept and ACW timeout are set by editing the user afterwards. Source: [Add users to Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/user-management.html), Add a user individually, items 1-8. Checked 2026-09-30.
[^5]: The administrator is specified per identity option: Connect-managed takes a name, password and email; the directory option takes an existing directory username whose password the directory manages; SAML takes a name whose password the IdP manages. Source: [Create a Connect Customer instance](https://docs.aws.amazon.com/connect/latest/adminguide/amazon-connect-instances.html), Step 2: Add administrator > To specify the administrator for your instance, item 1. Checked 2026-09-30.
[^6]: The administrator named during instance creation is created as a Connect Customer user account and assigned the Admin security profile; choosing No administrator is also allowed. Source: [Create a Connect Customer instance](https://docs.aws.amazon.com/connect/latest/adminguide/amazon-connect-instances.html), Step 2: Add administrator, first paragraph and item 2. Checked 2026-09-30.
[^7]: In a user's settings the Phone Type is Soft phone or Desk phone; desk phones require the agent's number and incur outbound telephony charges when answering inbound calls, and for soft phone AWS recommends enabling persistent connection. Source: [Configure agent settings in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/configure-agents.html), To configure agent settings, item 5. Checked 2026-09-30.
[^8]: By default, users assigned the Agent security profile can access the Contact Control Panel and make outbound calls. Source: [Launch the Contact Control Panel (CCP) in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/launch-ccp.html), Bullet 'Configure permissions for the agents'. Checked 2026-09-30.
[^9]: The Contact Control Panel is launched at https://{instance name}.my.connect.aws/ccp-v2/, and an administrator can also open it from the phone icon in the upper right of the admin website. Source: [Launch the Contact Control Panel (CCP) in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/launch-ccp.html), Launch the Contact Control Panel, first paragraphs. Checked 2026-09-30.
[^10]: To claim a number, an Admin or a user with Phone numbers - Claim permission chooses Channels, Phone numbers, Claim a number, picks a toll-free or DID number (with an optional area code filter in the US), optionally attaches a flow in Flow / IVR, and saves. Source: [Get a local toll-free or DID Connect Customer phone number](https://docs.aws.amazon.com/connect/latest/adminguide/get-connect-number.html), Claim a number for your contact center, items 1-5. Checked 2026-09-30.
[^11]: Claiming and releasing numbers beyond 200% of the phone number quota within a rolling 180-day cycle blocks further claims until 180 days after the oldest released number, unless a quota exception is obtained. Source: [Get a local toll-free or DID Connect Customer phone number](https://docs.aws.amazon.com/connect/latest/adminguide/get-connect-number.html), Avoid being blocked from claiming or releasing too many numbers. Checked 2026-09-30.
[^12]: If no numbers display for a selected country or region, or a wanted area code or prefix is not listed, you request numbers by creating an Account and billing support case. Source: [Get a local toll-free or DID Connect Customer phone number](https://docs.aws.amazon.com/connect/latest/adminguide/get-connect-number.html), Claim a number for your contact center, Note under item 3. Checked 2026-09-30.
[^13]: The default quota for concurrent active calls per instance is 10, including PSTN and WebRTC calls, and calls beyond the quota receive a reorder (fast busy) tone. Source: [Connect Customer service quotas](https://docs.aws.amazon.com/connect/latest/adminguide/amazon-connect-service-limits.html), Connect Customer quotas table, row 'Concurrent active calls per instance'; How contacts are counted. Checked 2026-09-30.
[^14]: Since July 2023, claiming phone numbers located in countries outside the instance's AWS Region no longer requires an opt-in approval; AWS instead provides best-practice design guidance. Source: [Design your Connect Customer contact center for low latency to help ensure call quality](https://docs.aws.amazon.com/connect/latest/adminguide/low-latency-design.html), Note at top of page. Checked 2026-09-30.
[^15]: By default instance creation creates Amazon S3 buckets for call recordings, chat transcripts, exported reports, flow logs and email messages, with data encrypted using AWS KMS. Source: [Create a Connect Customer instance](https://docs.aws.amazon.com/connect/latest/adminguide/amazon-connect-instances.html), Step 4: Data storage, first paragraphs and bold note 'By default, Connect Customer creates buckets'. Checked 2026-09-30.
[^16]: Connect Customer includes four default security profiles: Admin, Agent (access to the CCP), CallCenterManager (user management, metrics and routing) and QualityAnalyst (metrics). Source: [Default security profiles in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/default-security-profiles.html), Default security profiles table. Checked 2026-09-30.
[^17]: A deleted Connect Customer instance cannot be restored, and its settings, data, metrics and reports become inaccessible; flow-log CloudWatch log groups must be deleted separately if no longer needed. Source: [Delete your Connect Customer instance](https://docs.aws.amazon.com/connect/latest/adminguide/delete-connect-instance.html), Important things to know, bullets 1 and 3. Checked 2026-09-30.
[^18]: Deleting a Connect Customer instance releases its claimed phone numbers back to inventory, and callers to a released number hear that it is not a working number. Source: [Delete your Connect Customer instance](https://docs.aws.amazon.com/connect/latest/adminguide/delete-connect-instance.html), Delete your Connect Customer instance, first list. Checked 2026-09-30.
[^19]: A directory cannot be unbound from a Connect Customer instance after it has been associated, and only one directory can be added to an instance. Source: [Use an existing directory for identity management in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/directory-service.html), Limitations list at end of page. Checked 2026-09-30.
[^20]: A Directory Service directory can be associated with only one Connect Customer instance at a time; to use it with a different instance you must delete the instance it is already associated with. Source: [Use an existing directory for identity management in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/directory-service.html), Use an existing directory for identity management, first paragraph. Checked 2026-09-30.
[^21]: A directory used for Connect Customer identity management must be associated with your AWS account, set up in Directory Service, and active in the same AWS Region in which you create the instance. Source: [Plan your identity management in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/connect-identity-management.html), Link to an existing directory bullet, second paragraph. Checked 2026-09-30.
[^22]: The Directory Service directory types supported for Connect Customer identity are AWS Managed Microsoft Active Directory, AD Connector, and Simple AD. Source: [Use an existing directory for identity management in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/directory-service.html), List following 'The following Directory Service directories are supported'. Checked 2026-09-30.
[^23]: AWS advises calculating latency in a test environment before production, using the Connect Customer Endpoint Test Utility to check latency. Source: [Design your Connect Customer contact center for low latency to help ensure call quality](https://docs.aws.amazon.com/connect/latest/adminguide/low-latency-design.html), Best practices list, item 2 sub-item 1. Checked 2026-09-30.
[^24]: A claimed or ported number is attached to a flow under Channels, Phone numbers, choosing the number and selecting the flow in Flow / IVR, and only published flows appear in that list. Source: [Attach a claimed or ported phone number to a flow in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/associate-claimed-ported-phone-number-to-flow.html), To associate a claimed or ported phone number with a published flow, items 1-4. Checked 2026-09-30.
[^25]: To allow a user to create a Connect Customer instance, the user must have the permissions granted by the AmazonConnect_FullAccess IAM policy. Source: [Create a Connect Customer instance](https://docs.aws.amazon.com/connect/latest/adminguide/amazon-connect-instances.html), Things to know before you begin, second bullet. Checked 2026-09-30.
[^26]: Apple Messages for Business, SMS, WhatsApp Business Messaging and push notifications integrations are not available in AWS GovCloud (US-West). Source: [Availability of Connect Customer features by Region](https://docs.aws.amazon.com/connect/latest/adminguide/regions.html), Messaging integrations table, AWS GovCloud (US-West) row. Checked 2026-09-30.
[^27]: Hours of operation are specified on a queue and can be tested in flows with the Check hours of operation block to branch contacts outside hours. Source: [Set the hours of operation and time zone for a queue using Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/set-hours-operation.html), Set the hours of operation item 8; How flows use hours of operation. Checked 2026-09-30.
[^28]: Hours of operation are created under Routing, Hours of operation, Add new set of hours, by entering a name, choosing a time zone and setting operational hours, by an Admin or a user with Routing - Hours of operation - Create permission. Source: [Set the hours of operation and time zone for a queue using Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/set-hours-operation.html), Set the hours of operation, items 1-7. Checked 2026-09-30.
[^29]: To move a Connect Customer instance to a different identity management option you must delete the instance and create a new one, and deleting the instance loses its configuration settings and metrics data. Source: [Plan your identity management in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/connect-identity-management.html), Plan your identity management in Connect Customer, second paragraph. Checked 2026-09-30.
[^30]: The identity management option chosen when a Connect Customer instance is created cannot be changed after the instance is created. Source: [Create a Connect Customer instance](https://docs.aws.amazon.com/connect/latest/adminguide/amazon-connect-instances.html), Step 1: Set identity, first paragraph; repeated in Things to know before you begin and Step 5. Checked 2026-09-30.
[^31]: Instance creation offers three identity management options: Store users in Connect Customer, Link to an existing directory (a Directory Service directory), and SAML 2.0-based authentication using an existing identity provider. Source: [Create a Connect Customer instance](https://docs.aws.amazon.com/connect/latest/adminguide/amazon-connect-instances.html), Step 1: Set identity > To configure identity management for your instance, item 3. Checked 2026-09-30.
[^32]: The default quota is 2 Connect Customer instances per Region, adjustable at the account level. Source: [Connect Customer service quotas](https://docs.aws.amazon.com/connect/latest/adminguide/amazon-connect-service-limits.html), Connect Customer quotas table, row 'Connect Customer instances per Region'. Checked 2026-09-30.
[^33]: AWS recommends anchoring either the phone numbers or the agents in the AWS Region where they are geographically located; if both are in a different Region from the instance, WebRTC round-trip network latency is extended above 500 ms and call quality may suffer. Source: [Design your Connect Customer contact center for low latency to help ensure call quality](https://docs.aws.amazon.com/connect/latest/adminguide/low-latency-design.html), Best practices list, item 1 and sub-item 1.1. Checked 2026-09-30.
[^34]: AWS recommends under 500 ms end-to-end latency for best call quality, says up to 900 ms combined network and telephony latency may be acceptable, and states that above 900 ms causes significant delay between agents and customers. Source: [Design your Connect Customer contact center for low latency to help ensure call quality](https://docs.aws.amazon.com/connect/latest/adminguide/low-latency-design.html), Best practices list, item 2 sub-items 3-4 and Important box. Checked 2026-09-30.
[^35]: AWS advises using a default security profile only if it matches what users need and otherwise creating a security profile that grants only the needed permissions, and notes new permissions are added regularly. Source: [Default security profiles in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/default-security-profiles.html), First paragraph and Note below table. Checked 2026-09-30.
[^36]: Country or region regulations often require a local office address and specific identification documents to order or port phone numbers, and addresses claimable without presence such as PO boxes are not valid in any country. Source: [Region requirements for ordering and porting phone numbers in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/phone-number-requirements.html), Introductory paragraphs and Important box. Checked 2026-09-30.
[^37]: The published ID requirements for ordering and porting numbers apply to all AWS Regions except Africa (Cape Town) and AWS GovCloud (US-West) unless noted otherwise per country. Source: [Region requirements for ordering and porting phone numbers in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/phone-number-requirements.html), Third introductory paragraph, bold sentence. Checked 2026-09-30.
[^38]: The default quota for phone numbers per instance is 10, and the 'You've reached the limit of Phone Numbers' error can appear even on a first claim and requires AWS Support to resolve. Source: [Connect Customer service quotas](https://docs.aws.amazon.com/connect/latest/adminguide/amazon-connect-service-limits.html), Connect Customer quotas table, row 'Phone numbers per instance'. Checked 2026-09-30.
[^39]: Amazon Connect Customer is the current name for the product previously called Amazon Connect; the name Amazon Connect now refers to a set of agentic AI solutions for different business functions. Source: [What is Connect Customer?](https://docs.aws.amazon.com/connect/latest/adminguide/what-is-amazon-connect.html), What is Connect Customer? > Note at top of page. Checked 2026-09-30.
[^40]: A queue is created under Routing, Queues, Add new queue, where you set hours of operation, outbound caller ID, maximum contacts and quick connects; the queue is automatically active. Source: [Create a queue using the Connect Customer admin website](https://docs.aws.amazon.com/connect/latest/adminguide/create-queue.html), To create a queue, items 2-3. Checked 2026-09-30.
[^41]: Because the only documented way to change an instance's identity option is to delete and recreate it, and the documentation describes no move operation, the AWS Region chosen at creation should be treated as fixed for the life of the instance (inferred). Source: [Delete your Connect Customer instance](https://docs.aws.amazon.com/connect/latest/adminguide/delete-connect-instance.html), Error message: Region Unsupported section (instance must be managed from the Region where it was created). Checked 2026-09-30.
[^42]: Connect Customer is available in US East (N. Virginia), US West (Oregon), Africa (Cape Town), Asia Pacific (Seoul, Singapore, Sydney, Tokyo), Canada (Central), Europe (Frankfurt, London) and AWS GovCloud (US-West). Source: [Availability of Connect Customer features by Region](https://docs.aws.amazon.com/connect/latest/adminguide/regions.html), Connect Customer availability by Region table. Checked 2026-09-30.
[^43]: After you release a claimed phone number you cannot claim the same phone number again. Source: [Get a local toll-free or DID Connect Customer phone number](https://docs.aws.amazon.com/connect/latest/adminguide/get-connect-number.html), How many phone numbers you can claim, first paragraph. Checked 2026-09-30.
[^44]: The channel set for a queue in a routing profile must also be enabled in the profile's Channel Settings, otherwise contacts from that channel will not be routed to agents. Source: [Create a routing profile in Connect Customer to link queues to agents](https://docs.aws.amazon.com/connect/latest/adminguide/routing-profiles.html), Queues table, Channels row. Checked 2026-09-30.
[^45]: A routing profile links queues to agents, and each agent is assigned exactly one routing profile. Source: [Create a routing profile in Connect Customer to link queues to agents](https://docs.aws.amazon.com/connect/latest/adminguide/routing-profiles.html), Introductory paragraphs. Checked 2026-09-30.
[^46]: A routing profile is created under Users, Routing profiles, Add routing profile, where you set channel availability and concurrency, add queues with channel, priority and delay, and choose a default outbound queue whose settings such as caller ID outbound contacts respect. Source: [Create a routing profile in Connect Customer to link queues to agents](https://docs.aws.amazon.com/connect/latest/adminguide/routing-profiles.html), To create a routing profile, items 1-4 and Queues table. Checked 2026-09-30.
[^47]: For a SAML instance the administrator user name entered at creation must exactly match a user name in the existing network directory, and there is no option to set a password for it. Source: [Configure SAML with IAM for Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/configure-saml.html), Select SAML 2.0-based authentication during instance creation. Checked 2026-09-30.
[^48]: A URL-encoded destination parameter on the SAML relay state URL, such as destination=%2Fccp-v2, can send users straight to a page like the CCP if their security profile grants access to it. Source: [Configure SAML with IAM for Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/configure-saml.html), Use a destination in your relay state URL. Checked 2026-09-30.
[^49]: For an AWS GovCloud instance the SAML relay state is https://console.amazonaws-us-gov.com/connect/federate/{instance-id}. Source: [Configure SAML with IAM for Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/configure-saml.html), Enable SAML federation between your identity provider and AWS, item 7, GovCloud paragraph. Checked 2026-09-30.
[^50]: SAML federation for Connect Customer requires creating a SAML identity provider in IAM and a single IAM role for SAML 2.0 federation whose policy allows connect:GetFederationToken for the instance, with the IdP's Application Start URL left blank. Source: [Configure SAML with IAM for Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/configure-saml.html), Enable SAML federation between your identity provider and AWS, items 1-5. Checked 2026-09-30.
[^51]: Connect Customer does not support reverse (service-provider-initiated) SAML federation; users must authenticate at the identity provider, and attempting to log in directly produces a Session Expired message. Source: [Configure SAML with IAM for Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/configure-saml.html), Important notes, bullet 4. Checked 2026-09-30.
[^52]: With SAML 2.0-based authentication users can log in to Connect Customer only through the link configured in the identity provider, and AWS advises configuring the SAML environment before creating the instance. Source: [Plan your identity management in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/connect-identity-management.html), SAML 2.0-based authentication bullet. Checked 2026-09-30.
[^53]: AWS recommends overriding the IdP's Assertion Consumer Service URL from the global sign-in endpoint (hosted in US East) to https://{region-id}.signin.aws.amazon.com/saml for the instance's Region, and adding that URL to a multivalued SAML:aud condition in the role trust policy. Source: [Configure SAML with IAM for Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/configure-saml.html), Important notes bullet 5; Configure the identity provider to use regional SAML endpoints, items 1-2. Checked 2026-09-30.
[^54]: The IdP relay state for a commercial-Region SAML instance is https://{region-id}.console.aws.amazon.com/connect/federate/{instance-id}, where the instance ID is the value after /instance in the instance ARN. Source: [Configure SAML with IAM for Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/configure-saml.html), Enable SAML federation between your identity provider and AWS, item 7 and Note. Checked 2026-09-30.
[^55]: SAML sessions in Connect Customer expire 12 hours after login and the user is logged out even if on a call, so agents working longer must log out of Connect Customer and the IdP and log in again before expiry. Source: [Configure SAML with IAM for Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/configure-saml.html), SAML user logging in and session duration > About session expiration. Checked 2026-09-30.
[^56]: SAML users in Connect Customer have no primary email address or password and log in with a username, and they need a secondary email configured to receive email notifications. Source: [Add users to Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/user-management.html), Add a user individually, Note under item 4. Checked 2026-09-30.
[^57]: For SAML instances the Connect Customer user name must exactly match the RoleSessionName attribute in the IdP's SAML response, user names are case sensitive, and a user with no matching account sees an Access denied message. Source: [Configure SAML with IAM for Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/configure-saml.html), Important notes, bullets 3 and 6; Add users to your Connect Customer instance. Checked 2026-09-30.
[^58]: Agents using the CCP with a softphone must use Chrome, Edge or Firefox and grant the browser microphone access. Source: [Launch the Contact Control Panel (CCP) in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/launch-ccp.html), Paragraph beginning 'Agents can use the CCP with a softphone'. Checked 2026-09-30.
[^59]: A security profile is created under Users, Security profiles, Add new security profile by a user with Security profiles - Create permission, and choosing an action automatically selects the actions it depends on, such as View when Edit is chosen. Source: [Create a security profile in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/create-security-profile.html), How to create security profiles, items 2-7; Required permissions to create security profiles. Checked 2026-09-30.
[^60]: The Set telephony step of instance creation offers Receive inbound calls, Make outbound calls, Enable early media, and multi-party calls and chats of up to six participants with enhanced monitoring. Source: [Create a Connect Customer instance](https://docs.aws.amazon.com/connect/latest/adminguide/amazon-connect-instances.html), Step 3: Set telephony > To configure telephony options for your instance, items 1-5. Checked 2026-09-30.
[^61]: After you claim a number you can immediately call it, and Connect Customer uses the default flows to power that initial experience; to test a customized flow you assign a number to it and call that number. Source: [Design your Connect Customer contact center for low latency to help ensure call quality](https://docs.aws.amazon.com/connect/latest/adminguide/low-latency-design.html), Best practices list, item 3. Checked 2026-09-30.
[^62]: Only phone numbers claimed in or ported to the Amazon Connect instance can be used as the outbound caller ID number, unless an external number has been activated for custom caller ID through an AWS Support case. Source: [Set up outbound caller ID in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/queues-callerid.html), Outbound caller ID number. Checked 2026-09-30.
[^63]: In a routing profile's Queues section each queue entry has a Channels setting, a Priority in which a lower number is handled first, and a Delay in seconds that is the minimum time a contact must be in the queue before it is routed to an available agent; the channel chosen for the queue must also be enabled in the profile's Channel Settings or contacts on it are not routed. Source: [Create a routing profile in Connect Customer to link queues to agents](https://docs.aws.amazon.com/connect/latest/adminguide/routing-profiles.html), To create a routing profile, Queues table. Checked 2026-09-30.
