Each Azure subscription has a directory associated to it. The directory stores information about users who have access to the Azure portal. The directory is part of Windows Azure Active Directory (WAAD), which is a multitenant version of Active Directory available in Windows Server.
When a subscription is created, a directory named Default Directory
is created. The directory has two default roles:
Global administrator
User
Other roles shown in the multifactor authentication window of the directory are as follows:
Sign-in allowed users
Billing administrators
Password administrators
Service administrators
User management administrators
Global administrator
In WAAD, only the global administrator role is used. The other roles in Microsoft Azure Active Directory are used by Office 365.