Subject: AFSS Reader Group membership not syncing to amazonbi — users redirected to wrong account
Hi team,
We’re experiencing an issue where users added to the QuickSight reader permissions group (via AFSS) are not being provisioned as Readers in the amazonbi account, despite active group membership for 5+ days.
Context: The affected users are provisioned in two QuickSight accounts: wwcs-quicksight and amazonbi. They need access to both — wwcs-quicksight for their team’s internal dashboards, and amazonbi for a shared Quick App.
Symptoms:
- Users are in the correct AFSS reader group and membership is active
- When accessing quicksight.aws.amazon.com with account name “amazonbi”, they either:
- Get an IAM error:
not authorized to perform quicksight:DescribeAccountSubscription - Get redirected to the wwcs-quicksight account instead of amazonbi, where they see: “You must have permissions quicksight:CreateUser, quicksight:CreateAdmin or quicksight:CreateReader within your IAM policy”
- Get an IAM error:
- It appears that having an existing session/provisioning in wwcs-quicksight interferes with the login flow to amazonbi — the system defaults to the wrong account
What we’ve tried:
- Confirmed AFSS group membership is active (not pending)
- All affected users are L3+ Amazonians
- Logging out of wwcs-quicksight first doesn’t resolve the issue
- Filed a SIM ticket (CTI: Corporate Systems > AmazonBI > Access Inquiry) to ee-fai-quicksight — no response after multiple business days
Questions:
- Is anyone else experiencing issues when users need access to multiple QuickSight accounts (e.g. wwcs-quicksight + amazonbi)?
- Does AFSS group sync work differently when a user is already provisioned in another account?
- Is there a way to trigger a manual provisioning sync, or does a QuickSight Admin need to manually register the users?
- What’s the correct escalation path when ee-fai-quicksight doesn’t respond?
This is blocking 10+ team members from accessing a production Quick App. Any guidance appreciated.
Thanks!