You would probably have the same service, as it is for the same network device. Then in the enforcement policy, make sure it's set to 'First Match' and put the most specific rule first (Part of OU AND Machine Authenticated) and the less specific (Machine Authenticated) below that.
BTW, if you reuse the OU membership in other services, like for other brand switches, or WLAN, you could create a Role Mapping and do a 'if OU contains <whatever>' assign role 'member-of-ou'; then in enforcement if role eq member-of-ou and role eq machine authenticated -> enforcement profile for that; second just role eq machine auth -> profile for that.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check
https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
------------------------------