
Explanation:
Box 1: No
User1 is Global Administrator.
By default, Global Administrator and other administrator roles do not have permissions to read, define, or assign custom security attributes.
Note: The roles that apply to configuration sets are:
Attribute Definition Administrator
Attribute Assignment Administrator
Attribute Definition Reader
Attribute Assignment Reader
Box 2: No
User2 is Attribute Definition Administrator.
Attribute Definition Administrator
Users with this role can define a valid set of custom security attributes that can be assigned to supported Microsoft Entra objects. This role can also activate and deactivate custom security attributes.
Box 3: Yes
User3 is Attribute assignment Administrator.
Attribute Assignment Administrator
Users with this role can assign and remove custom security attribute keys and values for supported Microsoft Entra objects such as users, service principals, and devices.
Reference:
https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/permissions-reference