Hi! To be sure I understand it correctly (because the subject says Azure ADDS) that you likely provisioned Azure AD Domain Service and then joined a VM to this domain, if yes then AAD connect is not suitable for this architecture. AADDS is a managed domain service for supporting legacy application for customer's benefit when they do lift & shift, and all high privileged accounts (EA, DA, etc) are locked out with Microsoft.
https://learn.microsoft.com/en-us/azure/active-directory-domain-services/synchronization
Thanks!