

# Testing the new Connect Customer sign-in experience
<a name="new-signin-experience"></a>

## Overview
<a name="new-signin-overview"></a>

Connect Customer is implementing an enhanced sign-in experience with improved security features. This topic explains how to test the new sign-in interface before the mandatory transition.

**Important**  
The new sign-in experience applies only to non-SAML (Connect Customer managed or existing directory) instances. If your instance uses SAML 2.0-based authentication, this change does not apply to you.

### New sign-in experience features
<a name="new-signin-features"></a>

The enhanced sign-in experience introduces the following features:
+ Comprehensive AWS CloudTrail event logging for sign-in activities
+ Enhanced accessibility features for all users
+ Additional security measures to protect your instance

Starting April 7, 2026, all newly created instances will use the new sign-in experience by default. Existing instances can begin testing the new experience on this date.

### Migration timeline
<a name="new-signin-migration-timeline"></a>

The migration to the new sign-in experience will occur in the following phases:
+ **April 7, 2026** – All newly created instances will use the new sign-in experience by default.
+ **July 7, 2026** – Instances that can already reach the new sign-in endpoints will be automatically migrated.
+ **October 7, 2026** – All remaining instances will be migrated. Ensure your network configuration is updated before this date to maintain uninterrupted access.

## Testing instructions
<a name="new-signin-testing"></a>

Before testing the new sign-in experience, allowlist the following endpoints to make sure they are accessible from your network:
+ `*.apps.signin.aws`
+ `*.signin.aws`
+ `*.threat-mitigation.aws.amazon.com`
+ `*.s3.dualstack.{{[Region]}}.amazonaws.com`

  Replace {{[Region]}} with us-east-1, us-west-2, and the location of your Connect Customer instance.

If you are an AWS GovCloud (US) user, also allowlist the following endpoints:
+ `*.signin-fips.amazonaws-us-gov.com`
+ `*.apps.signin-fips.aws-us-gov.com`
+ `*.apps.signin.aws.rproxy.goskope.com-us-gov.com`

**To test the new sign-in experience**

1.  Navigate to the Connect Customer console `https://{{[region]}}.console.aws.amazon.com/connect/v2/app/instances?region={{[region]}}` 

    For example, if operating in the us-west-2 region, the URL will be `https://us-west-2.console.aws.amazon.com/connect/v2/app/instances?region=us-west-2`

1. **Locate your instance URL** – Your Connect Customer instance URL will be in one of these formats:
   + `https://{{[instance-alias]}}.my.connect.aws`
   + `https://{{[instance-alias]}}.awsapps.com/connect`

   You can find this in the AWS console as shown in the following image.  
![The Connect Customer instances page showing the instance access URL.](https://docs.aws.amazon.com/connect/latest/adminguide/images/new-signin-instance-url.png)

1. **Add the testing parameter** – To access the new sign-in experience, append `?use-new-experience=true` to your instance's login URL:
   + `https://{{[instance-alias]}}.my.connect.aws/login?use-new-experience=true`

   or
   + `https://{{[instance-alias]}}.awsapps.com/connect/login?use-new-experience=true`

   The new experience looks like the following:  
![The new sign-in page showing the username field.](https://docs.aws.amazon.com/connect/latest/adminguide/images/new-signin-username.png)  
![The new sign-in page showing the password field.](https://docs.aws.amazon.com/connect/latest/adminguide/images/new-signin-password.png)

1. **Verify access** – Navigate to the modified URL and attempt to sign in using your existing credentials. Confirm that you can successfully access your Connect Customer instance.

## Testing recommendations
<a name="new-signin-recommendations"></a>

We recommend the following when testing the new sign-in experience:
+ **Browser coverage** – Test across the browsers your agents and administrators commonly use, including Chrome, Firefox, Safari, and Edge.
+ **Browser autofill** – Test your browser's saved credentials and autofill behavior on the new unified sign-in page. Confirm that your browser or password manager correctly populates the username and password fields, and that you can sign in successfully. If the fields do not autofill as expected, update your saved credentials for the new sign-in URL.
+ **Network configurations** – Test from behind your corporate firewall and VPN to confirm the required URLs are accessible.
+ **User roles** – Verify sign-in with different user roles, including agents, supervisors, and administrators.
+ **Password reset flow** – Test the password reset process to confirm that reset emails from `no-reply@signin.aws` are received and not blocked by email filters.

## Resetting a forgotten password
<a name="new-signin-reset-password"></a>

If you do not remember your password, you can reset it directly from the new sign-in page. You do not need to contact your administrator to regain access.

**To reset your password**

1. On the sign-in page, choose **Reset password**.

1. Enter your username when prompted, and then follow the on-screen instructions.

1. Check your email for a password reset message from `no-reply@signin.aws`. If you do not see the email, check your spam or junk folder. Confirm that messages from this address are not blocked by your email filters.

1. Follow the link in the email to create a new password, and then sign in using your new credentials.

## Support resources
<a name="new-signin-support"></a>

When seeking support, prepare your instance ID and document any error messages you encounter. Screenshots of issues can be helpful for faster resolution. For more information about contacting AWS Support, see [Get administrative support for Connect Customer](get-admin-support.md).

## FAQs
<a name="new-signin-faqs"></a>

### Will I need to update any configuration on my end to support this new page?
<a name="new-signin-faq-config"></a>

You might need to allowlist the URLs listed in the [Testing instructions](#new-signin-testing) section to ensure the new sign-in endpoint is accessible from your network.

### Will my existing users credentials be affected in any way by this update?
<a name="new-signin-faq-users"></a>

No, your existing users can continue signing in with their existing credentials using the new experience.

### Will the password reset email come from a different email address?
<a name="new-signin-faq-email"></a>

Yes, you'll receive reset password emails from `no-reply@signin.aws` going forward.

### Do I need to add new IP ranges to my allowlist for the new sign-in endpoints?
<a name="new-signin-faq-ip-ranges"></a>

Yes. You need to add the S3 IP ranges to your allowlist for us-east-1, us-west-2, and the Region where your Connect Customer instance is located. The existing EC2 and CLOUDFRONT IP ranges in the AWS [ip-ranges.json](https://docs.aws.amazon.com/vpc/latest/userguide/aws-ip-ranges.html) file already cover the other new sign-in endpoints (`*.apps.signin.aws`, `*.signin.aws`, `*.threat-mitigation.aws.amazon.com`).

For more information about IP-based allowlisting for Connect Customer, see [Set up your network to use the Connect Customer Contact Control Panel (CCP)](ccp-networking.md).