The difference is when you're running in Splunk Cloud you have sc_admin, which is different from the admin role. See the description found in the Splunk Cloud Service Description : https://docs.splunk.com/Documentation/SplunkCloud/latest/Service/SplunkCloudservice#Users_and_authentication
" For the customer's administrator users, Splunk Cloud provides the sc_admin role, which has the capabilities required to administer Splunk Cloud. You can use the Splunk Cloud sc_admin role for your administrator to perform self-service tasks such as installing apps, creating and managing indexes, and managing users and their passwords. Splunk Cloud does not support direct access to infrastructure, so you do not have command-line access to Splunk Cloud. This means that any supported task that requires command-line access is performed by Splunk on your behalf."
... View more