# Step 2: Deploy the IDC stack

Install the IDC CloudFormation stack in the organisation management account.

#### How to Install this Stack

1. Login to the AWS Management Console using the **Organisation Management Account.**
2. Navigate to the **CloudFormation** page.
3. Click **Create Stack** and select **With new resources (standard)**.
4. For Template Source, select **Amazon S3 URL** and enter the CloudFormation Template URL shown below and click **Next**.
5. On the **Specify Stack** page, enter the stack name '**SandboxStudio-IDC**' and use the parameters shown below.

---

#### CloudFormation Template URL

```
https://sandbox-studio-software-dist.s3.amazonaws.com/versions/<VERSION>/SandboxStudio-IDC.template.json
```

For more information on how to find the latest version, [click here](https://docs.sandboxstudiosoftware.com/books/installation-guide/page/aws-cloudformation-templates "AWS CloudFormation templates").

---

#### Parameters

<div class="_tableContainer_sk2ct_1" id="bkmrk-key-what-to-enter-na"><div class="_tableWrapper_sk2ct_13 group flex w-fit flex-col-reverse" tabindex="-1"><table class="w-fit min-w-(--thread-content-width)" data-end="6285" data-start="5393" style="width: 119.167%;"><thead data-end="5491" data-start="5393"><tr data-end="5491" data-start="5393"><th class="align-left" data-col-size="sm" data-end="5414" data-start="5393" style="width: 37.3063%;">**Key**</th><th class="align-left" data-col-size="sm" data-end="5491" data-start="5414" style="width: 62.6937%;">**What to enter**</th></tr></thead><tbody data-end="6285" data-start="5591"><tr data-end="5689" data-start="5591"><td data-col-size="sm" data-end="5612" data-start="5591" style="width: 37.3063%;">**Namespace**</td><td data-col-size="sm" data-end="5689" data-start="5612" style="width: 62.6937%;">Use the same namespace you used in step 1.</td></tr><tr data-end="5788" data-start="5690"><td data-col-size="sm" data-end="5711" data-start="5690" style="width: 37.3063%;">**HubAccountId**</td><td data-col-size="sm" data-end="5788" data-start="5711" style="width: 62.6937%;">12‑digit Hub account ID</td></tr><tr data-end="5888" data-start="5789"><td data-col-size="sm" data-end="5810" data-start="5789" style="width: 37.3063%;">**IdentityStoreId**</td><td data-col-size="sm" data-end="5888" data-start="5810" style="width: 62.6937%;">From IAM Identity Center</td></tr><tr data-end="5988" data-start="5889"><td data-col-size="sm" data-end="5910" data-start="5889" style="width: 37.3063%;">**SsoInstanceArn**</td><td data-col-size="sm" data-end="5988" data-start="5910" style="width: 62.6937%;">From IAM Identity Center</td></tr><tr data-end="6087" data-start="5989"><td data-col-size="sm" data-end="6010" data-start="5989" style="width: 37.3063%;">**AdminGroupName**</td><td data-col-size="sm" data-end="6087" data-start="6010" style="width: 62.6937%;">Default: `<Namespace>_SsAdminsGroup`</td></tr><tr data-end="6186" data-start="6088"><td data-col-size="sm" data-end="6111" data-start="6088" style="width: 37.3063%;">**ManagerGroupName**</td><td data-col-size="sm" data-end="6186" data-start="6111" style="width: 62.6937%;">Default: `<Namespace>_SsManagersGroup`</td></tr><tr data-end="6285" data-start="6187"><td data-col-size="sm" data-end="6208" data-start="6187" style="width: 37.3063%;">**UserGroupName**</td><td data-col-size="sm" data-end="6285" data-start="6208" style="width: 62.6937%;">Default: `<Namespace>_SsUsersGroup`</td></tr></tbody></table>

</div></div>---

#### About this Stack

**Purpose**

- Sets up **IAM Identity Center groups**, permissions and roles used by Sandbox Studio. You add users to these groups to grant role‑based access to the application.

**Where to deploy**

- **Organisation management account**, even if you have delegated IAM Identity Center administration to another account.

**What it creates**

- A set of IDC groups aligned to Sandbox Studio roles (for example: administrators, managers, end users).

**Validation checks**

- Groups appear in **IAM Identity Center**.
- Assigning a user to a group grants the expected application role after sign‑in.

**Tips**

- Add test users to each group and confirm the correct level of access in the UI before onboarding wider teams.

<div _ngcontent-ng-c3818350049="" class="markdown markdown-main-panel enable-updated-hr-color" dir="ltr" id="bkmrk--3"></div><div _ngcontent-ng-c3818350049="" class="markdown markdown-main-panel enable-updated-hr-color" dir="ltr" id="bkmrk--4"><div _ngcontent-ng-c3818350049="" class="markdown markdown-main-panel enable-updated-hr-color" dir="ltr" id="bkmrk--5"></div></div><div _ngcontent-ng-c3818350049="" class="markdown markdown-main-panel enable-updated-hr-color" dir="ltr" id="bkmrk--6"></div>