If you are a Global Administrator in Azure AD, you can change access levels of subscription administrators who has owner level permissions in the subscription.
You need to elevate the access to perform the changes. Global Administrator will be assigned the User Access Administrator role in Azure at root scope (/)
Check the link below to learn, how to elevate the access
elevate-access-global-admin
Visit the subscription and select 'Deny Assignments' as below to refine the roles of the subscription owners
Add a custom role where you can deny the access to the resources in the subscription
----------
--please don't forget to upvote
and Accept as answer
if the reply is helpful--