You have an Azure subscription named Sub1. Sub1 contains two resource groups named RG1 and RG2.
You need to ensure that Global Administrators can manage all resources contained in RG1 and RG2.
Solution: From the Azure Active Directory Properties blade, you enable Access management for Azure resources.
Does this solution meet the goal?
This solution does meet the goal. The Access management for Azure resources property, located in the Azure Active Directory (Azure AD) tenant's settings, ensures that Azure AD users assigned to the Global Administrator role maintain full control over all subscription resources in the event that the identity is removed from Azure resource-level access lists. In keeping with least-privilege security, Microsoft recommends that you enable this property only when necessary.