Hello Mahdi,
Thanks for your question.
User1 has access to all resources within the hierarchy because they belong to the Tenant Root Group (ie everything under the tenant group) but User2 has access to all resources under Management Group 1, including Subscription1 and Resource1.
You can mark it 'Accept Answer' and 'Upvote' if this helped you
Regards,
Abiola