Azure role-based access control (Azure RBAC) inheritance
RBAC roles assigned high can grant access broadly through inheritance. Azure role-based access control (Azure RBAC) equals permissions by scope. Assigning at management group can grant access across subscriptions. Use least privilege and narrow scopes first. Widen scope only when it's truly needed.

