An Azure platform as a service offer that is used to deploy web and cloud applications.
We have a local AD sub-domain named andes.baipro.com. When it was created a user was created that belonged to the AADDS Service Administrators Group, which has the ability to manage anything in the sub domain.
For some unknown reason that user became "inoperative". The user exists in AD users but cannot be used for login and is no longer in the AADDS Service Administrators Group. Because it is a local domain, users from baipro.com that are in the AADDS Service Administrators Group do not have permission to change members of AADDS Service Administrators Group in andes.baipro.com.
We have a andes.baipro.com user that is in the AAD DC Administrators Group, so we can still add users, but that user does not have permission to maintain membership in AADDS Service Administrators Group.
Effectively we are locked out of the top-level administration function for the sub-domain.
We need Azure support to add selected users to the AADDS Service Administrators Group to regain control of the andes.baipro.com sub-domain.
If you look at the screen shot, you can see there are no members in the AADDS Service Administrators Group except dcaasadmin, which we cannot use to change membership in the group.
The basic issue is we do not have a user in the AADDS Service Administrators Group that can maintain membership in that group as well as other groups like AAD DC Administrators.