Hi @Toyoshima Kaori • Thank you for reaching out.
For this purpose, you need to have Read userCertificate and Write userCertificate permissions but on the managed domains, you aren't granted administrative privileges and you cannot delegate/assign these permissions. Group membership of users and groups that are synchronized from Azure Active Directory to Azure AD Domain Services cannot be modified because their source of origin is Azure Active Directory.
Within the managed domain, Domain Administrator and Enterprise Administrator privileges aren't available for you to use. Even in hybrid deployments, members of the domain administrator or enterprise administrator groups in your on-premises Active Directory are also not granted domain/enterprise administrator privileges on the managed domain.
-----------------------------------------------------------------------------------------------------------
Please "Accept the answer" if the information helped you. This will help us and others in the community as well.