I created a user in IAM Identity Center. I assigned them to a group and the group to my account. I assigned a persmission set AdministratorAccess (managed by AWS). The user can log in using mfa, choose the account, choose the permission set and they are shown 400 error - bad request.
I tried a different browser, a private mode etc. I tried a different email address. I deleted and created IAM Identity Center again. Nothing helps. I cannot see any reason for that.
I created the user to protect my root account as proposed in some guide here.
Can you help, pls?