@tommeadon I tend to agree, but in my experience that's mostly true because of my experience of "legacy ADDS" from back in the day. Azure IAM is similar to it.
AWS IAM is very different, not necessarily centralised (although it can be) and often confusing to people with different experience.
That said, especially cross-account IAM still makes my brain melt.