Hello, I tried to merge or match an Office 365 email account with an on-premises user account.
This is the error I get. Thank you for your input.
PS C:\Windows\system32> update-mguser -userid "******@tustinca.org" -onpremisesImmutableid "xxxxxxxxxxxxxtR6A=="
update-mguser : Insufficient privileges to complete the operation.
Status: 403 (Forbidden)
ErrorCode: Authorization_RequestDenied
Date: 2026-01-16T00:14:27
Headers:
Transfer-Encoding : chunked
Vary : Accept-Encoding
Strict-Transport-Security : max-age=31536000
request-id : 6176ee9e-302a-4668-82f5-d1c3a4198acb
client-request-id : 033ed772-3e29-452f-9128-9d74d3907b0f
x-ms-ags-diagnostic : {"ServerInfo":{"DataCenter":"West US
3","Slice":"E","Ring":"2","ScaleUnit":"000","RoleInstance":"PH1PEPF0001162D"}}
x-ms-resource-unit : 1
Cache-Control : no-cache
Date : Fri, 16 Jan 2026 00:14:27 GMT
At line:1 char:1
- update-mguser -userid "******@company.com" -onpremisesImmutableid ...
-
+ CategoryInfo : InvalidOperation: ({ UserId = fmor...softGraphUser }:<>f__AnonymousType52`
3) [Update-MgUser_UpdateExpanded], Exception
+ FullyQualifiedErrorId : Authorization_RequestDenied,Microsoft.Graph.PowerShell.Cmdlets.UpdateMgUse
r_UpdateExpanded
PS C:\Windows\system32> get