AWS connect: Clarification on IP allowlisting for new sign-in endpoints
Summary
Added FAQ confirming no new IP ranges are needed for sign-in endpoints, as they use existing EC2/CloudFront ranges
Security assessment
Documents network security best practices by clarifying IP allowlisting requirements for authentication endpoints, preventing potential access blocks
Evidence
No. The new sign-in endpoints (`*.apps.signin.aws`, `*.signin.aws`, `*.threat-mitigation.aws.amazon.com`) use IP addresses that are already covered by the existing EC2 and CLOUDFRONT IP ranges in the AWS [ip-ranges.json](https://docs.aws.amazon.com/vpc/latest/userguide/aws-ip-ranges.html) file.
Diff
diff --git a/connect/latest/adminguide/new-signin-experience.md b/connect/latest/adminguide/new-signin-experience.md index 970573992..da68d28dd 100644 --- a//connect/latest/adminguide/new-signin-experience.md +++ b//connect/latest/adminguide/new-signin-experience.md @@ -140,0 +141,6 @@ Yes, you'll receive reset password emails from `[email protected]` going forwa +### Do I need to add new IP ranges to my allowlist for the new sign-in endpoints? + +No. The new sign-in endpoints (`*.apps.signin.aws`, `*.signin.aws`, `*.threat-mitigation.aws.amazon.com`) use IP addresses that are already covered by the existing EC2 and CLOUDFRONT IP ranges in the AWS [ip-ranges.json](https://docs.aws.amazon.com/vpc/latest/userguide/aws-ip-ranges.html) file. If your network already allows traffic to those ranges, you do not need to make additional IP range configuration changes for the new sign-in experience. + +For more information about IP-based allowlisting for Connect Customer, see [Set up your network to use the Connect Customer Contact Control Panel (CCP)](./ccp-networking.html). +