Custom Roles AssignableScope for root ("/")
Currently Custom roles cannot have an AssignableScope set to root ("/"). Capability must be addded to have all subscriptions federating to a certain Azure AD tenant inherit a custom role. Maybe the AssignableScope parameter must be modified to also accept a tenant id or name for the scope of the role. The global admin of the tenant must be afforded the privilege to create this role.