NOTE: This article applies only to Salesforce Voice (formerly Service Cloud Voice) with Amazon Connect or Salesforce Voice with Partner Telephony using Amazon Connect contact centers.
Error Message: Insufficient Privileges
Cause: The user lacks access to the Contact Center's SSO Connected App. This occurs when:
Resolution: Perform either of the following:
Error Message: Data Not Available — The data you were trying to access could not be found. It may be due to another user deleting the data or a system error.
Cause: The self-signed certificate selected in the Contact Center's SSO Connected App was deleted, causing a bad reference when the connected app generates the SAML XML for the user.
How to validate: Navigate to the {contact_center_internal_name} Connected App and edit it. If the Idp Certificate field shows an ID starting with 0P1... instead of a certificate name, the linked certificate was deleted.
Resolution: Create or identify another self-signed certificate in Setup → Certificate and Key Management, then update it as the Idp Certificate in the Contact Center Connected App.
Error Message: Response signature invalid (Service: AWSSecurityTokenV20111201; Status Code: 400; Error Code: InvalidIdentityToken)
Cause: Certificate mismatch between the Salesforce Connected App and the AWS-side SAML metadata.
Resolution:
Error Message: Issuer not present in specified provider (Service: AWSOpenIdDiscoveryService; Status Code: 400; Error Code: AuthSamlInvalidSamlResponseException)
Cause: SAML Metadata mismatch — the Issuer value passed by the Connected App does not match the Issuer (EntityId XML attribute) in the AWS-side Identity Provider's SAML metadata.
Resolution:
Error Message: Access denied. Your account has been authenticated, but has not been onboarded to this application. Contact your Administrator to onboard to Amazon Connect and try again.
Cause: The user is not added to the Contact Center in Amazon Connect's configuration.
Resolution:
After applying the resolution steps for the applicable error scenario, the affected user opens the Telephony Provider Settings link and is taken to the Amazon Connect Home Page.
Before logging back into Omni-Channel, perform the following:
Still seeing a grayed-out dial-pad after successful manual SSO test? Check Salesforce Voice: Amazon Connect CCP loading issue with "net::ERR_NAME_NOT_RESOLVED" error for metadata-level contact center issues.
005316458

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.