Select your cookie preferences

We use essential cookies and similar tools that are necessary to provide our site and services. We use performance cookies to collect anonymous statistics, so we can understand how customers use our site and make improvements. Essential cookies cannot be deactivated, but you can choose “Customize” or “Decline” to decline performance cookies.

If you agree, AWS and approved third parties will also use cookies to provide useful site features, remember your preferences, and display relevant content, including relevant advertising. To accept or decline all non-essential cookies, choose “Accept” or “Decline.” To make more detailed choices, choose “Customize.”

Remove user and group access to an AWS account

Focus mode
Remove user and group access to an AWS account - AWS IAM Identity Center

Use this procedure to remove single sign-on access to an AWS account for one or more users and groups in your connected directory. Alternatively, you can use the delete-account-assignment AWS CLI.

Note

When you need to deprovision IAM Identity Center users or groups, you should first remove any assignments of permission sets from your users and groups before deleting the users and groups.

To remove user and group access to an AWS account
  1. Open the IAM Identity Center console.

  2. In the navigation pane, under Multi-account permissions, choose AWS accounts.

  3. On the AWS accounts page, a tree view list of your organization appears. Select the name of the AWS account that contains the users and groups for whom you want to remove single sign-on access.

  4. On the Overview page for the AWS account, under Assigned users and groups, select the name of one or more users or groups, and choose Remove access.

  5. In the Remove access dialog box, confirm that the names of the users or groups are correct, and choose Remove access.

PrivacySite termsCookie preferences
© 2025, Amazon Web Services, Inc. or its affiliates. All rights reserved.