A municipal landing zone must apply strict SCPs to production courts accounts while giving experimental AI sandboxes looser guardrails. Which OU design best supports that governance model?
Select an answer to reveal the explanation.
Short Explanation
Courts and a research sandbox are not the same hallway — different locks belong on different wings. Put them in separate OUs so production courts get tight SCPs and AI sandboxes get a different rule set.
Full Explanation
Organizational Units let administrators attach differentiated SCPs to groups of accounts. Separating regulated production courts from experimental sandboxes enables preventive guardrails appropriate to each risk tier. A single shared OU forces one-size SCPs that either block legitimate sandbox work or weaken production protections. SCPs attach to OUs, roots, or accounts — not to IAM users on EC2 — and Organizations remains foundational for multi-account governance.