The rights you are granted on the domain in AAD DS are limited, you are not a Domain Admin, which I would imagine this tool believes you are. You are granted only specific rights to undertake operations that are allowed in AAD DS. This includes managing users and groups, GPO's, OU's, DNS and a few other things.
You have no rights to access or modify the schema.
If you need more rights than this then you would need to look at using IaaS domain controllers and not AAD DS.