View or search account assignments
You can view account assignments in several ways.
Console
For all procedures in this section, sign in to the management account (or delegated admin account), select the Region where account access manager is enabled, and navigate to Account access manager in the IAM console.
AWS CLI
The following commands illustrate how to retrieve account assignments using different filters. The CLI refers to assignments as entitlements.
Retrieve first 100 assignments (entitlements) for a specific account
aws account-access list-entitlements \ --region <Region> \ --application-arn "<Account_access_manager_ARN>" \ --filter '{ "principalRole": { "account": "<ACCOUNT_ID>" } }' \ --max-results 100
Retrieve all assignments (entitlements) for a specific user
aws account-access list-entitlements \ --region <Region> \ --application-arn "<Account_access_manager_ARN>" \ --filter '{ "principal": { "type": "USER", "id": "<USER_ID>" } }'
Retrieve all assignments (entitlements) for a specific group
aws account-access list-entitlements \ --region <Region> \ --application-arn "<Account_access_manager_ARN>" \ --filter '{ "principal": { "type": "GROUP", "id": "<GROUP_ID>" } }'