Upon creating an aks cluster and integrating with azure ad by following instructions at https://docs.microsoft.com/en-us/azure/aks/aad-integration, I was able to successfully establish RBAC on azure ad users and user groups.
Unfortunately, this process doesn't work for a service principal created in azure ad
I see a feature request submitted, https://feedback.azure.com/forums/914020-azure-kubernetes-service-aks/suggestions/37411549-having-the-ability-to-let-service-principal-non-i