DrVoIP
  • Amazon Connect
    • Get Started
      • Why Amazon Connect
      • Deployment & Quickstart
      • Fixed-Fee Packages
      • Migration from Legacy Systems
      • DIY Call Center Kit
    • Grow & Support
      • Managed Service & Support
      • CRM Integrations
      • Pricing
      • Case Studies
      • Chatbot Design
    • Real Deployment
      • 40+ agents, one AWS Connect instance
  • AI Solutions
    • Smart Answer
      • Why AI Solutions
      • Knowledge AI (RAG)
      • AI-Assisted Agents
      • AI Readiness Checklist
      • Chatbot Design
    • Smart Action
      • Agentic Automation
      • AI in Amazon Connect
      • AI Modernization Brief
      • AI Performance Checklist
    • Applied AI
      • AI that answers, or AI that acts?
      • AI Insights & Analytics
  • Cloud Services
    • Infrastructure & Security
      • Why Cloud Services
      • Network & Security Hardening
      • Cloud & Virtualization Migration
    • Custom Engineering
      • Phone System Support & Maintenance
      • Custom Application & Integration Development
      • Chat, Messaging & Web Meetings
    • Client Result
      • Cloud engineering under the hood
  • About
    • About Peter
    • Resources
    • Blog
    • Contact
  • Book a Strategy Call
  • Menu Menu

Configure Amazon Connnect for SSO using Microsoft Azure

Amazon Connect, Deployment & Automation, Technical Managers
Helpful tips sticky note

Azure AD Configuration

There is work that needs to be done on both sides and typically two different engineers will be working the issue, one on Azure and one in Connect.  Step one is for the Azure engineer to setup a new application using the login link that agents would normally use to login to the Connect instance.  You can find this on the Amazon Connect home page inside the AWS Management console.   The Azure engineer will then provide a Metadata.XML file back to the AWS Engineer.

Step 2 AWS IAM Provider Configuration

 

  1. Log in to AWS and open the IAM
  2. Click on Identity providers and then Create Provider.
  3. Choose the Provider Type as SAML.
  4. Enter Provider Name, such as “Azure AD”
  5. Upload a Federation Metadata XML (downloaded from previous step).
  6. Click Create Provider

Current companion resource: Plan identity and access requirements with the 2026 Planning Guide.

 

Step 3 AWS IAM Role Configuration ( More Information Here: https://docs.aws.amazon.com/connect/latest/adminguide/configure-saml.html )

  1. From the IAM/roles console Create a New Role
  2. Select SAML 2.0 Federation trusted entity type
  3. Select the Azure AD SAML provider from previous step
  4. Select Allow Programmatic and AWS Management Console access. The rest will auto-fill.
  5. On the Attach Permissions Policies Page create a policy like this:

{

"Version": "2012-10-17",

"Statement": [

{

"Sid": "Federation",

"Effect": "Allow",

"Action": "connect:GetFederationToken",

"Resource": [

"arn:aws:connect:YOUR_REGION:YOUR_ACCOUNT_ID:instance/YOUR_INSTANCE_ID/user/${aws:userid}"

]

}

]

}

  1. After policy is created, go back to Create Role tab, reload the policy list, and select your new policy.
  2. Set a role name and description, then click Create Role
  3. Open the new role and copy the Role ARN into notepad. Switch to the trust relationships tab and copy the Provider ARN into notepad.

Step 4 Create User for Azure to pull Roles for Users

1 - Create Policy "List Roles"

2 - Create User with programmatic access and attach the policy with the Access and Secret Keys

3 - Send me the Provider ARN and Role ARN back to the Azure engineer along with the User and Access Keys where the balance of the configuration is completed

The Azure engineer will then complete the Provisioning section setting the mode to Auto

 

 

July 2, 2020/by Peter
Tags: Agent Login, AWS IAM, AWSConnect, Microsoft Azure, SAML, Single Sign-On
https://drvoip.com/wp-content/uploads/2019/07/helpful-tips-sticky-note-926.webp 226 223 Peter /wp-content/uploads/2026/10/drvoip-logo-18.webp Peter2020-07-02 07:37:222020-07-02 07:37:22Configure Amazon Connnect for SSO using Microsoft Azure
You might also like
2025 Amazon Connect Contact Center Planning Guide cover 2025 DrVoIP Contact Center Planning Guide!
Contact center terminology word cloud ShoreTel Enteprise Contact Center Tool Bar Setup Options
Contact center and mobile pricing illustration The ROI of the Dextr Dashboard for Amazon Connect Call Centers!
Cybersecurity training and certification illustration Why work with DrVoIP?
Cisco Agent Desktop login screen UCCX Cheat Sheet - Agent Log-in in using Extension Mobility!
DrVoIP 2019 Amazon Connect Service Delivery Partner certificate A Call Center for Cheap, Penny Pinching, Tightwads on a budget!
AI answers and actions contact center illustration Your Amazon Connect Platform Changed in 2026. Did Anyone Tell You?
Contact center terminology word cloud Deploy an Amazon Connect Contact Center for $195?
DrVoIP logo

Building cloud communications and contact center solutions since 2008.

DrVoIP on YouTube
Peter Buswell on LinkedIn

Services

Amazon Connect
AI Solutions
Cloud Services
Case Studies

Company

About Peter
Resources
Blog
Contact

Talk to us

844-4DrVoIP
grace@drvoip.com

© 2026 DrVoIP. All rights reserved.

FAQsCookies PolicyPrivacy PolicyTerms of Use
Link to: Amazon Connect Lets folks text a request for call back! Link to: Amazon Connect Lets folks text a request for call back! Amazon Connect Lets folks text a request for call back!Helpful tips sticky note Link to: Direct Extension Dialing and queue based Voice Mail for Amazon Connect! Link to: Direct Extension Dialing and queue based Voice Mail for Amazon Connect! Telephone keypad call optionsDirect Extension Dialing and queue based Voice Mail for Amazon Connect!
Scroll to top Scroll to top Scroll to top

This site uses cookies. By continuing to browse the site, you are agreeing to our use of cookies.

Accept settingsHide notification onlySettings

Cookie and Privacy Settings



How we use cookies

We may request cookies to be set on your device. We use cookies to let us know when you visit our websites, how you interact with us, to enrich your user experience, and to customize your relationship with our website.

Click on the different category headings to find out more. You can also change some of your preferences. Note that blocking some types of cookies may impact your experience on our websites and the services we are able to offer.

Essential Website Cookies

These cookies are strictly necessary to provide you with services available through our website and to use some of its features.

Because these cookies are strictly necessary to deliver the website, refusing them will have impact how our site functions. You always can block or delete cookies by changing your browser settings and force blocking all cookies on this website. But this will always prompt you to accept/refuse cookies when revisiting our site.

We fully respect if you want to refuse cookies but to avoid asking you again and again kindly allow us to store a cookie for that. You are free to opt out any time or opt in for other cookies to get a better experience. If you refuse cookies we will remove all set cookies in our domain.

We provide you with a list of stored cookies on your computer in our domain so you can check what we stored. Due to security reasons we are not able to show or modify cookies from other domains. You can check these in your browser security settings.

Other external services

We also use different external services like Google Webfonts, Google Maps, and external Video providers. Since these providers may collect personal data like your IP address we allow you to block them here. Please be aware that this might heavily reduce the functionality and appearance of our site. Changes will take effect once you reload the page.

Google Webfont Settings:

Google Map Settings:

Google reCaptcha Settings:

Vimeo and Youtube video embeds:

Privacy Policy

You can read about our cookies and privacy settings in detail on our Privacy Policy Page.

Privacy Policy
Accept settingsHide notification only