
Explanation:
Box 1: /subscriptions/c276fc76-9cd4-44c9-99a7-4fd71546436e
There is nothing called "resourceGroups" only or "resourceGroups/*" . You can specify either a subscription, specific resource group, management group or specific resource. for example it should "/subcription/subcription_id/resourceGroups/resource_group_name" Box 2: Microsoft Authorization The AssignableScopes property specifies the scopes (management groups, subscriptions, or resource groups) where this role definition can be assigned. You can make the role available for assignment in only the management groups, subscriptions, or resource groups that require it. You must use at least one management group, subscription, or resource group.
Not Actions: An array of strings that specifies the control plane actions that are excluded from the allowed Actions.
Reference:
https://github.com/MicrosoftDocs/azure-docs/blob/master/articles/role-based-access-control/role- definitions.md#role-definition-structure
https://docs.microsoft.com/en-us/azure/role-based-access-control/role-
definitions#assignablescopes