You used to be able to let them know you were going to do certain kinds of pen-tests, unless port scanning is just one of those things never allowed
You still can, but that's for pentests _targetting_ AWS hosted infrastructure. They've always frowned upon using AWS to target _other_ services, however.
oof, how was that ultimately resolved? Hopefully a warning from support and a re-enabled account?
Nope! Afaik they did not get the account re-enabled, at least for the next few months!