A resource group is exactly what the name states a place for a pool of related items. Once the resource group is created the Azure AD Domain Services, network security group, virtual services and more can be added to the resource group.
One of the first items I needed to setup and understand was the Azure AD Domain Services. I look at Azure ADDS as a layer added onto Azure Active Directory. This service allows you to have an Azure resource that can be used to connect a on premises environment or to use the setup like I designed using the Azure virtual Windows Servers to create my environment.
The management of the Network Security Group is like operating a virtual firewall to control the inbound and outbound network traffic to the internal virtual network via a hosted external IP address. One of the tasks in setting up the lab I am working on was enabling traffic for port 3389 to allow RDP to my internal virtual server.