

# Remove user and group access to an Amazon Web Services account
<a name="howtoremoveaccess"></a>

Use this procedure to remove single sign-on access to an Amazon Web Services account for one or more users and groups in your connected directory. Alternatively, you can use the [delete-account-assignment](https://docs.amazonaws.cn//cli/latest/reference/sso-admin/delete-account-assignment.html) Amazon CLI.

**Note**  
When you need to deprovision IAM Identity Center users or groups, you should first [remove any assignments of permission sets](howtoremovepermissionset.md) from your users and groups before deleting the users and groups.

**To remove user and group access to an Amazon Web Services account**

1. Open the [IAM Identity Center console](https://console.aws.amazon.com/singlesignon).

1. In the navigation pane, under **Multi-account permissions**, choose **Amazon Web Services accounts**.

1. On the **Amazon Web Services accounts** page, a tree view list of your organization appears. Select the name of the Amazon Web Services account that contains the users and groups for whom you want to remove single sign-on access.

1. On the **Overview** page for the Amazon Web Services account, under **Assigned users and groups**, select the name of one or more users or groups, and choose **Remove access**.

1. In the **Remove access** dialog box, confirm that the names of the users or groups are correct, and choose **Remove access**. 