how to restrict AWS access permission for AAD users

I have integrated AAD authentication in AWS console using the following link and it is working fine. Allowed AAD users can able to login into this AWS portal.

It seems that these users are getting full administrative permission on this AWS account. How can I restrict the permission of these users in AWS? Means I wants to allow some of these users to admin privilage and another set of users are only workspace admin, Allow EC2 administration permission to some of the users etc..

 I am using  'Free Trial' with Office 365 subscription

