AFSS Reader Group membership not syncing to amazonbi — users redirected to wrong account

Subject: AFSS Reader Group membership not syncing to amazonbi — users redirected to wrong account

Hi team,

We’re experiencing an issue where users added to the QuickSight reader permissions group (via AFSS) are not being provisioned as Readers in the amazonbi account, despite active group membership for 5+ days.

Context: The affected users are provisioned in two QuickSight accounts: wwcs-quicksight and amazonbi. They need access to both — wwcs-quicksight for their team’s internal dashboards, and amazonbi for a shared Quick App.

Symptoms:

  • Users are in the correct AFSS reader group and membership is active
  • When accessing quicksight.aws.amazon.com with account name “amazonbi”, they either:
    • Get an IAM error: not authorized to perform quicksight:DescribeAccountSubscription
    • Get redirected to the wwcs-quicksight account instead of amazonbi, where they see: “You must have permissions quicksight:CreateUser, quicksight:CreateAdmin or quicksight:CreateReader within your IAM policy”
  • It appears that having an existing session/provisioning in wwcs-quicksight interferes with the login flow to amazonbi — the system defaults to the wrong account

What we’ve tried:

  • Confirmed AFSS group membership is active (not pending)
  • All affected users are L3+ Amazonians
  • Logging out of wwcs-quicksight first doesn’t resolve the issue
  • Filed a SIM ticket (CTI: Corporate Systems > AmazonBI > Access Inquiry) to ee-fai-quicksight — no response after multiple business days

Questions:

  1. Is anyone else experiencing issues when users need access to multiple QuickSight accounts (e.g. wwcs-quicksight + amazonbi)?
  2. Does AFSS group sync work differently when a user is already provisioned in another account?
  3. Is there a way to trigger a manual provisioning sync, or does a QuickSight Admin need to manually register the users?
  4. What’s the correct escalation path when ee-fai-quicksight doesn’t respond?

This is blocking 10+ team members from accessing a production Quick App. Any guidance appreciated.

Thanks!

Hi @nwaeldia and welcome to the Quick Community!
Please note that as the Community is a public facing forum, we would not have the ability to access private account information or to assist further with issues relating to your private account. In terms of something around permissions, I would suggest reaching out internally within your organization to get additional information regarding your account.

Thank you!