What it is
An AWS account is a hard wall. Billing, identities, and resources live inside it. An Azure subscription is the closest twin: a billing and access boundary under a tenant.
Folders, resource groups, and tags are labels. They help you find things. They do not stop a developer with the wrong permission from deleting production because test and prod share a fence.
Companies often start with one account or one subscription “to keep it simple.” Simple lasts until someone needs to try a dangerous change and has nowhere safe to try it.
Why it matters in the meeting
When JJ asks why a second subscription costs money, the honest answer is: it costs less than mixing the environments and finding out on a Friday.
Bart is not asking for a diagram of folders. He is asking whether a compromised test credential can reach production data. If prod and test share an account or subscription, the answer is often yes.
Real world
The classic accident is a cleanup script pointed at the wrong place. Same credentials. Same wall. Different intention. The script does not know you meant the sandbox.
Multi-account on AWS (Organizations) and management groups plus subscriptions on Azure exist so blast radius is a design choice, not a hope.
An account or subscription is a fence. A resource group is a sticky note on the fence. Do not store the production cattle and the science experiment in the same paddock and call it a strategy.
What to ask
- Are production and non-production in separate AWS accounts or Azure subscriptions, not just separate resource groups?
- If a test credential leaked tonight, what production data could it touch?
- Who is allowed to create a new account or subscription, and is that written down?
- Is billing visible per environment, or is finance reading one mystery invoice?
You just knew a little more Jack than you did five minutes ago.
All concepts