- Adds optional AWS account access management when creating a new IAM Identity Center instance
- Allows using IAM Identity Center solely for application SSO without provisioning service‑linked roles to member accounts
- Account management can be enabled later via instance settings or the UpdateInstance API