With a multi-account AWS environment managed using AWS Organizations and a security strategy incorporating SCPs, resource-based policies, identity-based policies, trust policies, and session policies, a solutions architect at SecureCorp needs to enable an IAM user in their development account (Account A) to assume a role in their production account (Account B). Which combination of steps must the solutions architect take to meet this requirement? (Choose three.)