Entra External ID: PATCH user identities returns 403 despite User.ManageIdentities.All

Darrel Remoroza 0 Reputation points
2026-10-01T01:57:25.9866667+00:00

Hi everyone,

We’re implementing Singpass authentication through a custom OIDC adapter in a Microsoft Entra External ID external tenant.

New customer signup through the provider works, and Entra creates a user with a federated identity. We now want to attach that provider identity to an existing email/password customer, preserving the customer’s Entra object ID and existing login method.

However, Microsoft Graph returns:
PATCH https://graph.microsoft.com/v1.0/users/{customer-object-id}

{

"error": {

"code": "Authorization_RequestDenied",

"message": "Insufficient privileges to complete the operation."

}

}

What we have verified

  • The application has admin-consented application permissions User.Read.All and User.ManageIdentities.All.
  • A freshly acquired client-credentials token contains both permissions in its roles claim.
  • GET requests for the customer succeed.
  • PATCHing displayName with its current value returns 204.
  • PATCHing the complete existing identities collection unchanged returns 403, even without adding a federated identity.
  • The collection includes both emailAddress and userPrincipalName.
  • The application failure reproduces in Laravel and Postman.
  • A separate Graph Explorer delegated test also returns 403. Graph Explorer shows User.ManageIdentities.All as consented; we are still verifying the signed-in administrator’s effective directory-role requirements.

The unchanged PATCH body has this structure, with actual existing values used during testing:

{

"identities": [

{

  "signInType": "emailAddress",

  "issuer": "<tenant>.onmicrosoft.com",

  "issuerAssignedId": "<existing-email>"

},

{

  "signInType": "userPrincipalName",

  "issuer": "<tenant>.onmicrosoft.com",

  "issuerAssignedId": "<existing-UPN>"

}

]

}

Microsoft Security | Microsoft Graph
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.