Hi,
Just goofing around, so there's probably a simple explanation, but I've just noticed that while logged into my own portal as global admin, I've gone into "Azure Active Directory -> Groups -> New" Group. Membership type is greyed out, but there is no switch option for "Azure AD roles can be assigned". Note that after creating a group I can view properties and see this switch, though disabled, and the switch can only be enabled during group creation.
Please advise if you spot something (obvious) I've overlooked, or is it not currently possible to create user-groups to manage user permissions efficiently in this manner?
I'll probably wind up kicking myself for missing something obvious, but we all have bad days :)