Is my understanding correct for AWS Account Management ?
As of now, IdentityNow don’t support multiple group objects, so IAM Users are managed as accounts and IAM groups are primary entitlement that are aggregated as a part of entitlement aggregation.
However as a part of account aggregation, associated AWS Managed Policies, Customer Manager Policies, Inline Policies are also aggregated and visible as entitlements.