For SAML instances the Connect Customer user name must exactly match the RoleSessionName attribute in the IdP's SAML response, user names are case sensitive, and a user with no matching account sees an Access denied message.

Checked 2026-09-30

Vendor
Amazon Web Services
Product
Amazon Connect Customer
Subsystem
SAML federation
Deployment
multi-tenant
Region
not restricted
Release range
current as of 2026-09-30
Checked
2026-09-30

Sources

Cite this note

APA

WarmTransfer. (2026, September 30). Setting up an Amazon Connect instance: source note amazon-connect-instance-setup-saml-username-match. WarmTransfer. https://warmtransfer.net/knowledge/claims/amazon-connect-instance-setup-saml-username-match

BibTeX

@misc{warmtransfer-claim-amazon-connect-instance-setup-saml-username-match,
  title  = {Setting up an Amazon Connect instance: source note amazon-connect-instance-setup-saml-username-match},
  author = {{WarmTransfer}},
  year   = {2026},
  url    = {https://warmtransfer.net/knowledge/claims/amazon-connect-instance-setup-saml-username-match},
  note   = {Source note amazon-connect-instance-setup-saml-username-match, checked 2026-09-30}
}

Read in context