Administrator role was cloned to manage Certificate Management and Identity Provider. However, the roles are inaccessible.
In order to manage SSO objects, such as the identity source or any other SSO configuration, the user must be a member of that 'administrators' group under the SSO domain.
Apply the account that requires the permissions to the Administrators group.