Got an official answer from Microsoft today:
I have confirmed that creating AAD users and groups is currently NOT supported when using Service Principal accounts. This particular limitation is only specific to database contained users.
Got an official answer from Microsoft today:
I have confirmed that creating AAD users and groups is currently NOT supported when using Service Principal accounts. This particular limitation is only specific to database contained users.