AWS Security ChangesHomeSearch

AWS connect: Clarification on IP allowlisting for new sign-in endpoints

Service: connect · 2026-07-29 · Documentation medium

File: connect/latest/adminguide/new-signin-experience.md · Type: network

Summary

Added FAQ confirming no new IP ranges are needed for sign-in endpoints, as they use existing EC2/CloudFront ranges

Security assessment

Documents network security best practices by clarifying IP allowlisting requirements for authentication endpoints, preventing potential access blocks

Evidence

No. The new sign-in endpoints (`*.apps.signin.aws`, `*.signin.aws`, `*.threat-mitigation.aws.amazon.com`) use IP addresses that are already covered by the existing EC2 and CLOUDFRONT IP ranges in the AWS [ip-ranges.json](https://docs.aws.amazon.com/vpc/latest/userguide/aws-ip-ranges.html) file.

Diff

diff --git a/connect/latest/adminguide/new-signin-experience.md b/connect/latest/adminguide/new-signin-experience.md
index 970573992..da68d28dd 100644
--- a//connect/latest/adminguide/new-signin-experience.md
+++ b//connect/latest/adminguide/new-signin-experience.md
@@ -140,0 +141,6 @@ Yes, you'll receive reset password emails from `[email protected]` going forwa
+### Do I need to add new IP ranges to my allowlist for the new sign-in endpoints?
+
+No. The new sign-in endpoints (`*.apps.signin.aws`, `*.signin.aws`, `*.threat-mitigation.aws.amazon.com`) use IP addresses that are already covered by the existing EC2 and CLOUDFRONT IP ranges in the AWS [ip-ranges.json](https://docs.aws.amazon.com/vpc/latest/userguide/aws-ip-ranges.html) file. If your network already allows traffic to those ranges, you do not need to make additional IP range configuration changes for the new sign-in experience.
+
+For more information about IP-based allowlisting for Connect Customer, see [Set up your network to use the Connect Customer Contact Control Panel (CCP)](./ccp-networking.html).
+