AWS Account Groups make it easier to target many AWS Accounts in a Rule. Once an AWS Account Group is created and selected in Rules, a User only has to modify the AWS Account Group to influence which AWS Accounts are targeted in those Rules.
AWS Account Groups are particularly helpful to organizations managing AWS Accounts that are logically or functionally related, such as all AWS Accounts for a particular application or possibly all development accounts across all applications for an entire organization.
By leveraging AWS Account Groups, rule creation and maintenance is simplified and AWS Account level user access control becomes easy to configure.
Creating an AWS Account Group
To get started, click the Team Menu, then Platforms
Navigate to AWS Account Groups
Click the Add Account Group button
Give your Account Group a name which describes the nature of the Accounts that it will contain e.g. non-production, sandbox, QA etc.
Using the selector choose the AWS Accounts you wish to add as members of this AWS Account Group
Click the Save Account Group button and you are ready to use this AWS Account Group in any Rule
Updating an AWS Account Group
Click on the ellipsis in the Actions column beside the AWS Account Group you wish to modify
Click Edit Account Group
Modify the Name or member AWS Accounts
Click Update Account Group
Using an AWS Account Group in a Rule
After you have created an AWS Account Group, click on Rules via the navigation bar
Click the Add a New Rule button
Click the Set Context badge
You should see your AWS Account Group's listed, and on hover you will notice you some visual feedback to indicate which AWS Accounts are part of the hovered AWS Account Group. Select your AWS Account Group
Finish all other parts of your Rule and click Save Rule. You are now using an AWS Account Group to target your AWS Accounts