If you run



  sacctmgr show association where parent=root

(and so forth recursively where parent= each of the children) do you find that 
these other accounts that can submit to the partition are not ultimately 
sub-accounts of "root"?

Quoting man 5 slurm.conf, concerning AllowAccounts, "This list is also 
hierarchical, meaning subaccounts are included automatically."

My slurm is 23.02.6,used EnforcePartLimits=ALL,Accounts outside of 
AllowAccounts can still submit。

What do you have for `sacctmgr list account`?  If "root" is your top-level 
(Slurm) (bank) account, AllowAccounts=root may just end up meaning any account. 
 To have AllowAccounts limit what users can submit, you'd need to name a 
lower-level Slurm (bank) account that only some users have an Association with.

