Thank you for posting this in Microsoft Q&A.
Yes, you can create custom RBAC policy depending on what user can and cannot access in resource.
You can refer below article to know more about the resources and permissions that can be assigned within resources.
https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles
And refer below article to get information about creating new custom role,
https://learn.microsoft.com/en-us/azure/role-based-access-control/custom-roles
Let me know if you have any further questions.
Please "Accept the answer" if the information helped you. This will help us and others in the community as well.