Loading
Salesforce now sends email only from verified domains. Read More
Agentforce Contact Center
Table of Contents
Select Filters

          No results
          No results
          Here are some search tips

          Check the spelling of your keywords.
          Use more general search terms.
          Select fewer filters to broaden your search.

          Search all of Salesforce Help
          Set Up External ID

          Set Up External ID

          For additional security, you can generate a unique external ID for your AWS account. When you enable an external ID, Service Cloud Voice can assume all cross-account management roles, including the provisioning role if used, and perform contact center admin actions in your AWS account only after external ID validation.

          Required Editions

          This article applies to:

          • Service Cloud Voice with Partner Telephony from Amazon Connect
          View supported editions.

          The external ID is valid for all the cross-account management roles associated with your Amazon contact center type.

          Amazon Contact Center Type External ID Applicable for Roles
          Partner Amazon Contact Center with a New Amazon Connect Instance
          • SCVProvisioningRole
          • AmazonConnectManagementRole
          • InstanceRecordingRole
          • SCVS3Role
          Partner Amazon Contact Center with an Existing Amazon Connect Instance Integrated by Salesforce
          • SCVProvisioningRole
          • AmazonConnectManagementRole
          • InstanceRecordingRole
          • SCVS3Role
          Partner Amazon Contact Center with an Existing Amazon Connect Instance Integrated by You through XML import
          • AmazonConnectManagementRole
          • UpdateCredentialRole
          • InstanceRecordingRole
          • SCVS3Role
          Note
          Note When you create or update an external ID, the external ID is valid only if you add it to the Trust Relationships policy for all the cross-account management roles, including the provisioning roles if used, in your AWS account.

          If you use the same IAM role ARN across multiple Salesforce orgs, the external ID mapped to the IAM role ARN in one org isn't accessible in a different org. In this case, each time you perform an action that requires a cross-account role in an org, update the external ID and save it in the Trust Relationships of all cross-account roles in your AWS account. Then use this external ID for performing the contact center admin actions.

          To disable the external ID for an AWS account, use the Configure External ID option in the Service Cloud Voice setup page.

          Set Up External ID for a New Contact Center

          While creating a contact center, you can configure an external ID if you haven't created any other contact center in the org that uses the AWS account associated with the selected IAM role ARN.

          While creating a Partner Amazon Contact Center with your existing Amazon Connect instance, you can configure an external ID for the AWS account as described in Use an Existing Amazon Connect Instance Integrated by Salesforce.

          While creating a Partner Amazon Contact Center with a new Amazon Connect instance, you can configure an external ID for the AWS account as described in Use a New Amazon Connect Instance.

          Set Up External ID for an Existing Contact Center

          You can use the Configure External ID option on the Service Cloud Voice setup page to create, update, or disable the external ID for your AWS account.

          To use the configure external ID option, you must have a Partner Amazon Contact Center created with a new or existing Amazon Connect instance integrated by Salesforce, or with an existing Amazon Connect instance integrated by you through XML import by providing either one of the AmazonConnectManagementRole, UpdateCredentialRole, InstanceRecordingRole, or SCVS3Role roles.

          To generate or update external ID, use the Configure External ID option in the Service Cloud Voice setup page.configure external id

          • Select the AWS account ID, and click Generate.generate external id
          • Save the external ID, and add the generated external ID in the Trusted Relationships in your AWS account. In your AWS account, add the external ID to all the management roles in the JSON file corresponding to the IAM role ARN.

          You can also use the Configure option to disable the external ID for an AWS account. Select the AWS account, and disable the External ID for the AWS account. Save the changes.

           
          Loading
          Salesforce Help | Article