Separate connections for two organisations


In one tenant I have two organizations: A and B, two connections CA and CB. When I allow auto membership for org B (CB), I am able to login into it with email for CA. The value of Microsoft Azure AD Domain in CA and CB are different.
Is it because the member of one connection is in the same tenant as another?

I want that the users of one organisation can login via a particular connection of this organization, and wouldn’t overlap with a group of the users from another.
Example: to org1, to org2