We already mentioned RBAC and how it can help with the management and administration of cloud resources. RBAC allows you to use AAD accounts to set up different roles and permissions on different levels of the Azure tenant. In order to provide user administration rights in the tenant, we must use the AAD blade. These rights are not transferred further. Under the tenant, we can have multiple subscriptions, and subscription engagement is done separately for each subscription.
Assigning a user to admin (or some other role) will automatically provide them with the same role on all resource groups and resources under that subscription. If we assign a role to a user on the resource group level, the role will be automatically provided for all resources in that resource group. Providing a role access to a single resource, will give the user access only to that...