You do not need to create SSO in different AWS account to restrict or Deny permissions to users for different services especially IAM and SSO itself.
sso
How to connect Visual Studio to AWS using AWS_SESSION_TOKEN of AWS SSO user
The user portal offers a single place to access all their assigned AWS accounts and applications. To access the AWS account or Applications, user logs into user portal.