Hello @Liz Wanless
Confirm that you are assigning the role at the subscription -> Access control (IAM) blade. Use the user's full email address (UPN) when searching for the user. As a workaround, assign the Contributor role to a temporary security group containing the user.
The Issue: If you are trying to add the user via the Azure Active Directory blade or the Users blade, you are managing the identity, not the access to the subscription resources. Role assignments must be done via the Access control (IAM) blade of the resource/scope you want to grant access to.
If the Answer is helpful, please click Accept Answer and Up-Vote, so that it can help others in the community looking for help on similar topics.