-
Notifications
You must be signed in to change notification settings - Fork 199
Description
{"level":"error","msg":"error deleting user","time":"2025-06-27T11:24:33Z","user":{"schemas":["urn:ietf:params:scim:schemas:core:2.0:User"],"userName":"@.com","name":{"familyName":"Admin","givenName":"AWS Control Tower"},"displayName":"AWS Control Tower Admin","active":true,"emails":[{"value":"@.com","type":"work","primary":true}],"addresses":[{"type":"work"}]}}
{"level":"fatal","msg":"Notifying Lambda and mark this execution as Failure: AccessDeniedException: User: arn:aws:sts::5*********:assumed-role/SSOSyncAppRole/serverlessrepo-SSOSync-SSOSyncFunction-ZXXXYjEbr80M is not authorized to perform: identitystore:DeleteUser on resource: arn:aws:identitystore::0**********:identitystore/d********* because no resource-based policy allows the identitystore:DeleteUser action ....}
But the IGNORE_USER is set in the template with the user