Explanation To assign a policy to the tenant root management group you have to be an administrator of an Azure subscription. To make a user an administrator of an Azure subscription, assign them the Owner role at the subscription scope. After that assignment user can configure access management for Azure resources. Reference: https://docs.microsoft.com/en-us/azure/role-based-access-control/role-assignments-portal