You are a platform engineer for a company on GitHub Enterprise Cloud. The enterprise owner has applied an enterprise-level security configuration that enables secret scanning push protection and sets it as the default for all new and existing repositories across every organization. Separately, an organization owner in one of the child organizations creates and applies their own organization-level security configuration that leaves push protection disabled, intending to roll it out gradually. A developer reports that push protection is still blocking commits in a repository within that organization. Assuming the enterprise configuration was applied with enforcement, why is push protection still active despite the organization's configuration?