Loading

SSO Authentication Error Scenarios for Salesforce Voice

Veröffentlichungsdatum: Jun 1, 2026
Beschreibung
NOTE: This article applies only to Salesforce Voice (formerly Service Cloud Voice) with Amazon Connect or Salesforce Voice with Partner Telephony using Amazon Connect contact centers.

Overview

When a contact center user opens a console app page with Omni-Channel present, Salesforce initiates the user's Single Sign-On (SSO) authentication to Amazon Connect in the background. If this background SSO authentication fails, the user continues to see a grayed-out dial-pad in the Omni-Channel widget despite being on an Available or Busy status.
This SSO authentication process can be tested manually with visual progress to identify and resolve any configuration-level issue for such a user.

Prerequisites

  1. As a Contact Center or Salesforce Admin, navigate to Salesforce Setup and search Contact Centers in Quick Find.
  2. Click on Amazon Contact Centers or Partner Telephony Contact Centers (based on your configured telephony model).
  3. Locate your Contact Center, right-click its Telephony Provider Settings link, and click Copy Link Address.
  4. Save the copied link and share it with the affected user.
Lösung

Error 1: Insufficient Privileges

Error Message: Insufficient Privileges
Cause: The user lacks access to the Contact Center's SSO Connected App. This occurs when:

  • The user's Salesforce Profile is not added to the SSO Connected App's Manage page, or
  • No permission set (such as the Salesforce Voice Permission Set) is assigned to the user to grant access to the SSO Connected App.

Resolution: Perform either of the following:

  • Add the user's Salesforce Profile to the SSO Connected App's access on its Manage page.
  • Assign the Salesforce Voice Permission Set (or equivalent) to the user to grant access to the SSO Connected App.

 

Error 2: Data Not Available

Error Message: Data Not Available — The data you were trying to access could not be found. It may be due to another user deleting the data or a system error.
Cause: The self-signed certificate selected in the Contact Center's SSO Connected App was deleted, causing a bad reference when the connected app generates the SAML XML for the user.
How to validate: Navigate to the {contact_center_internal_name} Connected App and edit it. If the Idp Certificate field shows an ID starting with 0P1... instead of a certificate name, the linked certificate was deleted.
Resolution: Create or identify another self-signed certificate in Setup → Certificate and Key Management, then update it as the Idp Certificate in the Contact Center Connected App.


Error 3: Response Signature Invalid (AWS InvalidIdentityToken)

Error Message: Response signature invalid (Service: AWSSecurityTokenV20111201; Status Code: 400; Error Code: InvalidIdentityToken)
Cause: Certificate mismatch between the Salesforce Connected App and the AWS-side SAML metadata.
Resolution:

  1. Check if the certificate has expired.
    1. If yes, follow steps 1–5 in Manage Contact Center Certificates.
  2. If the certificate has not expired:
    1. Verify that both the Salesforce Identity Provider and the Contact Center's SSO Connected App use the same self-signed certificate.
    2. Download the SAML metadata XML from the Salesforce Identity Provider page.
    3. Replace the SAML metadata in AWS Management Console → IAM → Identity Providers → SalesforceServiceVoiceIdp → Replace Metadata.

 


Error 4: Issuer Not Present (AuthSamlInvalidSamlResponseException)

Error Message: Issuer not present in specified provider (Service: AWSOpenIdDiscoveryService; Status Code: 400; Error Code: AuthSamlInvalidSamlResponseException)
Cause: SAML Metadata mismatch — the Issuer value passed by the Connected App does not match the Issuer (EntityId XML attribute) in the AWS-side Identity Provider's SAML metadata.
Resolution:

  1. Navigate to the SSO Connected App's View page and ensure the Issuer field is blank — this forces the connected app to use the org's My Domain as the issuer value.
  2. Verify that the Issuer field on the Manage page for the SSO Connected App is also set to the org's My Domain value.
  3. Verify the Salesforce Identity Provider's Issuer field is set to My Domain (to prevent recurrence after future contact center create or update operations).
  4. Download SAML metadata XML from the Salesforce Identity Provider page and replace the SAML metadata in AWS Management Console → IAM → Identity Providers → SalesforceServiceVoiceIdp → Replace Metadata.

Error 5: Access Denied — Account Not Onboarded to Amazon Connect

Error Message: Access denied. Your account has been authenticated, but has not been onboarded to this application. Contact your Administrator to onboard to Amazon Connect and try again.
Cause: The user is not added to the Contact Center in Amazon Connect's configuration.
Resolution:

  • Ensure the user has the correct Contact Center Admin or Agent permission set assigned and is successfully added to the Contact Center under Contact Center Users.
  • If the user is already part of the Salesforce Contact Center and still sees this error, try removing and re-adding the user to the contact center to sync Amazon Connect's user configuration.

 


Post-Fix Validation Steps

After applying the resolution steps for the applicable error scenario, the affected user opens the Telephony Provider Settings link and is taken to the Amazon Connect Home Page.
Before logging back into Omni-Channel, perform the following:

  1. Click your Amazon Connect username in the top-right corner to log out of Amazon Connect.
  2. Open the Console App page with Omni-Channel and open Browser Developer Tools.
  3. Right-click the browser's refresh button and choose Empty cache and hard reload.
  4. Let the Console App page load fully, then change your Omni-Channel status to Busy or Available for voice calls.


Still seeing a grayed-out dial-pad after successful manual SSO test? Check Salesforce Voice: Amazon Connect CCP loading issue with "net::ERR_NAME_NOT_RESOLVED" error for metadata-level contact center issues.

Nummer des Knowledge-Artikels

005316458

 
Laden
Salesforce Help | Article