It sounds like you're referring to an on-prem active directory issue.
Can you provide the docs that you're trying to follow?
I suggest posting your question against the active directory forums here :
As these forums are meant for Azure AD related issues.
More information on the Cert SErvices DCOM access group can be found here :