Skip to main content

Hello Salesforce Trailblazer Community,

We are building a proof of concept for Salesforce Voice with Partner Telephony from Amazon Connect, using Omni-Channel Unified Routing

. However, contact center users cannot sign in to the Amazon Connect CCP through Salesforce SSO. 

 

1. Technical Scenario & Error

When a rep sets an Omni-Channel presence status that includes the phone channel, the status remains at "Connecting".

The following errors and behaviors occur:

  • CCP: /ccp-v2 returns HTTP 401.
  • SAML SSO: The request to /idp/login?app=... fails.
  • Identity Provider Event Log: ErrorCode = NoAccess is recorded every time for the External Client App automatically created with the contact center.
  • Inbound test call: VoiceCall and PendingServiceRouting records are created, but no AgentWork record is created, and the call is never offered to the rep.

2. Environment Details

ItemConfiguration

 

Org Type | Developer Edition 

Telephony Model | Salesforce Voice with Partner Telephony from Amazon Connect 

Amazon Connect | New instance created from contact center setup 

Routing | Enhanced Omni-Channel / Omni-Channel Unified Routing 

Error | IdpEventLog: ErrorCode = NoAccess 

SSO | SsoType = Saml, InitiatedBy = IdP

3. Troubleshooting Steps Taken

We have already tried the following:

  1. Permission Sets and Licenses
    • Assigned Salesforce Voice Contact Center Admin (Partner Telephony) and Salesforce Voice Contact Center Rep (Partner Telephony) permission sets.
    • Assigned the Salesforce Voice User (Partner Telephony) permission set license.
  2. Contact Center User
    • Added the user as a contact center user.
    • Removed and re-added the user after assigning the Rep permission set.
  3. External Client App
    • Checked External Client App Manager.
    • The app is Managed, so its policies cannot be edited.
    • The app shows 0 permitted permission sets / profiles.
  4. Additional Permission Sets
    • Checked Assigned Connected Apps in the permission set, but no apps are available to select.
    • Assigned the auto-created permission set PartnerTelephonyCustomPsl, with no change.
  5. Identity Provider Settings
    • Changed Authenticate in to a new top-level window, with no change.
  6. Contact Center Recreation
    • Recreated the contact center, but the same issue was reproduced.

4. Questions

  1. How is access to this auto-created External Client App (SAML SSO) supposed to be granted to contact center users?
  2. Is there a way to grant access manually, given that the app is Managed and no permission sets or profiles are permitted?
  3. Is this a known limitation of Developer Edition orgs?

#Service Cloud Voice

0/9000