We plan to use an aws-* prefix on all Google Groups we want synced, and set --group-match accordingly. If ssosync only matches Google Groups with that prefix, will it completely ignore AWS Identity Center groups that don't match the filter (e.g. Control Tower groups like AWSControlTowerAdmins)? Or does ssosync still evaluate and potentially delete unmatched AWS groups?
We plan to use an aws-* prefix on all Google Groups we want synced, and set --group-match accordingly. If ssosync only matches Google Groups with that prefix, will it completely ignore AWS Identity Center groups that don't match the filter (e.g. Control Tower groups like AWSControlTowerAdmins)? Or does ssosync still evaluate and potentially delete unmatched AWS groups?