Hi,
#1
SCOM 2019 itself does not directly manage certificate templates or their permissions. In ADCS, you can restrict access to certificate templates by modifying the security permissions on the certificate templates.
#2
The Management Pack for Certificate Monitoring in SCOM 2019 can be used to monitor the certificate store on the Azure AD Connect server.