Using hierarchical management
So far, we have been assigning roles, policies, and blueprints at either the resource or subscription level. In larger organizations, managing user access at the subscription level could become tedious and difficult to maintain.
Consider a multi-national company, with offices worldwide and individual departments at each location, such as HR, IT, and sales. Each department may wish to have multiple subscriptions – each one hosting a particular solution. In these cases, you may still want to maintain central control over user access.
Continually assigning rights at the subscription level would not scale very well – especially when employees join and leave the company or perhaps change roles.
Azure offers a feature called management groups, which can be set up to mirror your company's structure – either geographical or departmental or combining the two.
Roles, policies, and blueprints can then be assigned at each level...