@ken5scal I tried the same steps in my test environment and encountered exactly the same error. As per our documentation, users and groups cannot be provisioned from AAD to AWS.
Note
Provisioning service will only import roles from AWS to Azure AD. This service will not provision users and groups from Azure AD back to AWS.
As you are successfully able to provision groups to AWS, I have reached out to our product team to confirm if there are any recent changes to the service. I will update you once I have the confirmation.