Azure Active Directory Domain Services Limitations

I work with Azure Active Directory (AAD) and enabled the Domain Services (AAD DS) feature to manage all my virtual machines and user-accounts. Domain Services is basically a Windows Domain Controller (in fact there are two of them), which provides Domain Join, LDAP and Authentication for your cloud hosted network and machines.
As a result, all users in the AAD can login to the Windows machines by using their AAD-Account.
From the documentation ( Your domain controller as a service “Lift-and-shift” apps to Azure more easily than everUse LDAP, Active Directory domain join, NTLM, and Kerberos authenticationRely on a managed, highly-available serviceGet started in minutes, pay as you goDevelop and test with no identity worriesManage Azure virtual machines effectively using Group Policy I use the following setup, often referred as "cloud-only organizations"

Known Limitations While still in the preview phase, I would …