Configuring AWS SSO from the CLI
We usually tear down what we have built in the Management Console to address the steps to recreate it from the CLI. However, this is a situation where AWS Organizations and AWS SSO's tight coupling already addressed many of the initial creation steps required to begin the tasks that we would perform from the AWS SSO service. We functionally already created a new AWS SSO service and identity store when we created an AWS organization using the command line. What is left to us to do with the CLI involves user assignment to member accounts. As such, to get a full picture of how to create an AWS SSO instance from scratch, refer back to the AWS Organization in the AWS CLI section earlier in this chapter.
The CLI does not have many options for account management for the identity store. Unlike Amazon Cognito, which is a full-featured platform for application identity use cases, AWS SSO uses the identity store primarily as its attribute and credential...