Hello TheCapricorn,
Since the your case is that you already has Microsoft Entra Connect working, you must also install Microsoft Entra Cloud Sync because you requires both features.
This means you requires the cloud sync to perform the group writeback. Then, strictly follow the guidelines in this document (https://learn.microsoft.com/en-us/entra/identity/hybrid/cloud-sync/migrate-group-writeback) for migrating existing groups or OUs from AADC to cloud synchronization.
Please also note that the group writebackscope for cloud sync provisioning to AD can only include on-premises synced users and/or extra cloud-created security groups.
Kindly let me know if this work for you and please let me know if you have any further questions.
If I have answered your question, please accept this answer as a token of appreciation and don't forget to give a thumbs up for "Was it helpful" and "Accept the anser"!
Best regards,