Hello Salesforce Trailblazer Community,
We are building a proof of concept for Salesforce Voice with Partner Telephony from Amazon Connect, using Omni-Channel Unified Routing
. However, contact center users cannot sign in to the Amazon Connect CCP through Salesforce SSO.
1. Technical Scenario & Error
When a rep sets an Omni-Channel presence status that includes the phone channel, the status remains at "Connecting".
The following errors and behaviors occur:
- CCP: /ccp-v2 returns HTTP 401.
- SAML SSO: The request to /idp/login?app=... fails.
- Identity Provider Event Log: ErrorCode = NoAccess is recorded every time for the External Client App automatically created with the contact center.
- Inbound test call: VoiceCall and PendingServiceRouting records are created, but no AgentWork record is created, and the call is never offered to the rep.
2. Environment Details
ItemConfiguration
Org Type | Developer Edition
Telephony Model | Salesforce Voice with Partner Telephony from Amazon Connect
Amazon Connect | New instance created from contact center setup
Routing | Enhanced Omni-Channel / Omni-Channel Unified Routing
Error | IdpEventLog: ErrorCode = NoAccess
SSO | SsoType = Saml, InitiatedBy = IdP
3. Troubleshooting Steps Taken
We have already tried the following:
- Permission Sets and Licenses
- Assigned Salesforce Voice Contact Center Admin (Partner Telephony) and Salesforce Voice Contact Center Rep (Partner Telephony) permission sets.
- Assigned the Salesforce Voice User (Partner Telephony) permission set license.
- Contact Center User
- Added the user as a contact center user.
- Removed and re-added the user after assigning the Rep permission set.
- External Client App
- Checked External Client App Manager.
- The app is Managed, so its policies cannot be edited.
- The app shows 0 permitted permission sets / profiles.
- Additional Permission Sets
- Checked Assigned Connected Apps in the permission set, but no apps are available to select.
- Assigned the auto-created permission set PartnerTelephonyCustomPsl, with no change.
- Identity Provider Settings
- Changed Authenticate in to a new top-level window, with no change.
- Contact Center Recreation
- Recreated the contact center, but the same issue was reproduced.
4. Questions
- How is access to this auto-created External Client App (SAML SSO) supposed to be granted to contact center users?
- Is there a way to grant access manually, given that the app is Managed and no permission sets or profiles are permitted?
- Is this a known limitation of Developer Edition orgs?
To resolve this authentication failure and restore the agent routing workflow, a salesforce administrator must explicitly grant the call center users access to the underlying app metadata. Navigate to Setup, type manage connected apps or external client apps manager in the quick find box, and click on the specific app