An API that connects multiple Microsoft services, enabling data access and automation across platforms
Entra External ID: PATCH user identities returns 403 despite User.ManageIdentities.All
Hi everyone,
We’re implementing Singpass authentication through a custom OIDC adapter in a Microsoft Entra External ID external tenant.
New customer signup through the provider works, and Entra creates a user with a federated identity. We now want to attach that provider identity to an existing email/password customer, preserving the customer’s Entra object ID and existing login method.
However, Microsoft Graph returns:
PATCH https://graph.microsoft.com/v1.0/users/{customer-object-id}
{
"error": {
"code": "Authorization_RequestDenied",
"message": "Insufficient privileges to complete the operation."
}
}
What we have verified
- The application has admin-consented application permissions
User.Read.AllandUser.ManageIdentities.All. - A freshly acquired client-credentials token contains both permissions in its
rolesclaim. - GET requests for the customer succeed.
- PATCHing
displayNamewith its current value returns 204. - PATCHing the complete existing identities collection unchanged returns 403, even without adding a federated identity.
- The collection includes both
emailAddressanduserPrincipalName. - The application failure reproduces in Laravel and Postman.
- A separate Graph Explorer delegated test also returns 403. Graph Explorer shows
User.ManageIdentities.Allas consented; we are still verifying the signed-in administrator’s effective directory-role requirements.
The unchanged PATCH body has this structure, with actual existing values used during testing:
{
"identities": [
{
"signInType": "emailAddress",
"issuer": "<tenant>.onmicrosoft.com",
"issuerAssignedId": "<existing-email>"
},
{
"signInType": "userPrincipalName",
"issuer": "<tenant>.onmicrosoft.com",
"issuerAssignedId": "<existing-UPN>"
}
]
}