Capabilities with Azure AD / O365

Hi,

I have a few questions in regards to Active Roles and Azure AD.

What are the limitations in what exactly can be managed with Active Roles in regards to Azure AD and Office 365 when in a hyrbid scenario using AAD Connect?

Is it possible for Exchange Onlne mailboxes to be managed (permissions, etc)?

What exactly do the following Azure related parameters do in the New-ADUser cmdlet as if I create a normal AD user that is in scope of AAD Connect then it will provision to Azure AD automatically.

-AzureUserAccountEnabled

-AzureOffice365enabled

Am I correct in saying that ARS cannot write any settings direct to the O365 recipients in a federated environment (even cloud only settings that aren't managed on-premises)?

Thank you in advance.