@Markus Bauer Thank you for reaching out to us, researched on your ask you can create users in managed domain in a custom OU. There are two OU's where AAD accounts and computers will be synced. you can't do anything there. However, you can create a custom OU and create objects in there.
Privileges required to create custom OU within managed domain.
Reference: [https://learn.microsoft.com/en-us/azure/active-directory-domain-services/administration-concepts
Let me know if you have any further questions, feel free to post back.