How to update the proxyAddresses of a Cloud-only Entra ID user without a Mailbox (not an Exchange Recipient)

Jason Smyth 26 Reputation points
2025-09-17T12:09:18.0566667+00:00

I currently have a client with an Entra ID user (not migrated from on-premises) that is cloud-based, but has proxyAddresses values assigned.

Now, I want to update the proxyAddresses through the Graph Explorer and have used this link as a guide: https://learn.microsoft.com/en-us/answers/questions/2280046/entra-connect-sync-blocking-user-creation-due-to-h.

Now this guide is suggesting you can use the BETA model and this URL format...

It states you can use that URL to do both 'GET' and 'PATCH' queries - the PATCH query being the one that will change the settings. You have to put forth a body for the proxyAddresses property in the PATCH query, which represents all of the addresses you want the user to utilise as proxy addresses.

Now the GET query works...

The PATCH query does not...

Screenshot provided:

User's image

Now, regarding the error message, I have applied ALL possible permissions in the 'Modify Permissions' tab. It is still erroring,

Now I cannot use Exchange Online PowerShell, as the user does not have a mailbox!

Aside from potentially using a license for Exchange Online or provisioning a mailbox for the user, and making the necessary changes, would the only other option be to delete/recreate the user?

@Steven Perazzo could you possibly give guidance here, please?

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

Answer accepted by question author
Andy David - MVP 160.3K Reputation points MVP Volunteer Moderator
2025-09-17T12:56:18.1733333+00:00

Yes, delete and recreate the user if you can not apply an Exchange License. I have never been able to make that work otherwise :) This hints that a license is required:

https://learn.microsoft.com/en-us/troubleshoot/entra/entra-id/user-prov-sync/proxyaddresses-attribute-populate

Was this answer helpful?

1 person found this answer helpful.

1 additional answer

Sort by: Newest
  1. Bendik Thorbjørnsen 0 Reputation points
    2026-09-30T06:19:20.6033333+00:00

    Can confirm this worked for me on a cloud-only Entra ID user (no Exchange Online license, RecipientType: User, no mailbox).

    Update-MgUser -ProxyAddresses via the Microsoft.Graph PowerShell SDK fails with the documented read-only error:

    Property 'proxyAddresses' is read-only and cannot be set.

    But issuing a raw PATCH against the beta endpoint succeeds where the v1.0 SDK cmdlet does not:

    $body = @{ proxyAddresses = @("SMTP:******@domain.com") } | ConvertTo-Json   Invoke-MgGraphRequest -Method PATCH -Uri "https://graph.microsoft.com/beta/users/{userId}" -Body $body -ContentType "application/json"

    A follow-up GET confirmed the full proxyAddresses array was replaced as requested.

    Worth noting for anyone relying on this: the official docs for proxyAddresses still list it as read-only in both v1.0 and beta, so this is undocumented behavior on Microsoft's part, not a supported write path. I'd treat it as something that could be locked down or changed without notice

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.