The default behavior is different depends on you are attempting to login the Classic Azure Portal (https://manage.windowsazure.com) or the New Azure Portal (https://portal.azure.com).
Classic Azure Portal:
Non-administrator Users cannot have any access to the Azure AD until you assign them a correct directory role (Global Admin for example).

New Azure Portal:
By default, users can see and access the Azure AD node, they can also see the other users/groups in this node although they don't have any permission to modify these resources, no matter if they have be assigned a directory role or not. You can also block the non-administrator's access to this node by configuring the "Administration Portal" option in the "User Settings" tab.