> For the complete documentation index, see [llms.txt](https://www.techwithtyler.dev/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://www.techwithtyler.dev/academy/aws-security-cookbook-by-tyler/aws-service-control-policies-scps/lab-deploying-aws-service-control-policies-scps-via-terraform.md).

# Lab: Deploying AWS Service Control Policies (SCPs) via Terraform

How to deploy AWS Service Control Policies via Terraform

{% hint style="success" %}

## Already Know Terraform?

If you're already familiar with Terraform, feel free to hop over to the [AWS Security Cookbook by Tyler GitHub repository](https://github.com/Ty182/AWS-Security-Cookbook-by-Tyler/tree/main) to grab and deploy the code. Otherwise, stick around and we'll walk through it together!&#x20;
{% endhint %}

## Overview

The Terraform code for this module has been left in a simplified state (i.e., not using modules, loops, or other advanced Terraform features) to be more easily accessible. You can customize it further to meet your specific requirements.

## Deployment

{% hint style="danger" %}

## Cost Alert

SCP policies are a feature of AWS Organizations and are free to use.

* See pricing details here: <https://docs.aws.amazon.com/organizations/latest/userguide/pricing.html>
  {% endhint %}

{% code overflow="wrap" %}

```bash
# clone the AWS Security Cookbook repository
git clone https://github.com/Ty182/AWS-Security-Cookbook-by-Tyler

# navigate to AWS Service Control Policies (SCPs) directory
cd AWS_Cookbook_by_Tyler/recipes/aws_serviceControlPolicies/code

# initialize the directory and download the required terraform providers
terraform init

# check formatting and validate the syntax is correct
terraform fmt && terraform validate

# check the resources that will be created
terraform plan 

# deploy the resources
terraform apply
```

{% endcode %}

* Once complete, head to the AWS Organizations console and check it out!

<figure><img src="https://2721275171-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F8yu8YbDfwd1VqEdUxGyA%2Fuploads%2FoWmh6L8wXIoXg1Dj4c2c%2FCleanShot%202025-02-26%20at%2017.18.21%402x.png?alt=media&amp;token=9ef4718c-ad08-4526-8d0f-8ac66d9184d8" alt=""><figcaption><p>AWS Organizations console showing Service Control Policies</p></figcaption></figure>

## Cleanup

{% hint style="danger" %}

## Clean up the resources

Avoid unnecessary costs by deleting the created resources

`terraform destroy`
{% endhint %}
