AWS Directory service admin does not have any privileges?
Noticed that AWS create delegated groups for you so after i added my users to the "AWS delegated administrators" group everything was fine.
As to why they lock you out of the real domain admin account and groups is beyond me though... sigh