Source record · tier 2 current vendor documentation
Configure SAML with IAM for Connect Customer
- Publisher
- Amazon Web Services
- URL
- https://docs.aws.amazon.com/connect/latest/adminguide/configure-saml.html
- Published
- unknown
- Updated
- unknown
- Accessed
- 2026-09-30
- HTTP status
- 200
- License
- AWS Site Terms (license of documentation text not verified this run); no-redistribution; short excerpts and locators only
Source notes citing this source
- For a SAML instance the administrator user name entered at creation must exactly match a user name in the existing network directory, and there is no option to set a password for it. in context
- A URL-encoded destination parameter on the SAML relay state URL, such as destination=%2Fccp-v2, can send users straight to a page like the CCP if their security profile grants access to it. in context
- For an AWS GovCloud instance the SAML relay state is https://console.amazonaws-us-gov.com/connect/federate/{instance-id}. in context
- SAML federation for Connect Customer requires creating a SAML identity provider in IAM and a single IAM role for SAML 2.0 federation whose policy allows connect:GetFederationToken for the instance, with the IdP's Application Start URL left blank. in context
- Connect Customer does not support reverse (service-provider-initiated) SAML federation; users must authenticate at the identity provider, and attempting to log in directly produces a Session Expired message. in context
- AWS recommends overriding the IdP's Assertion Consumer Service URL from the global sign-in endpoint (hosted in US East) to https://{region-id}.signin.aws.amazon.com/saml for the instance's Region, and adding that URL to a multivalued SAML:aud condition in the role trust policy. in context
- The IdP relay state for a commercial-Region SAML instance is https://{region-id}.console.aws.amazon.com/connect/federate/{instance-id}, where the instance ID is the value after /instance in the instance ARN. in context
- SAML sessions in Connect Customer expire 12 hours after login and the user is logged out even if on a call, so agents working longer must log out of Connect Customer and the IdP and log in again before expiry. in context
- For SAML instances the Connect Customer user name must exactly match the RoleSessionName attribute in the IdP's SAML response, user names are case sensitive, and a user with no matching account sees an Access denied message. in context
Cite this source record
APA
WarmTransfer. (2026, September 30). Configure SAML with IAM for Connect Customer. WarmTransfer. https://warmtransfer.net/knowledge/sources/aws-connect-configure-saml
BibTeX
@misc{warmtransfer-aws-connect-configure-saml,
title = {Configure SAML with IAM for Connect Customer},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/sources/aws-connect-configure-saml},
note = {Amazon Web Services, accessed 2026-09-30}
}