Hi @Spencer Guest ,
Thank you for reaching out to the Q&A community.
This permission error can happen when the syncing users with pre-existing administrative accounts.
Check if the users have admin count 1 in their attributes.
Its possible to configure the permission but its strongly recommended to Not sync users with on premises admin accounts.
On-prem admins should be dedicated accounts for administration with no applications access. You want the Azure AD admins to be cloud only accounts: https://video2.skills-academy.com/en-us/azure/active-directory/roles/security-planning#ensure-separate-user-accounts-and-mail-forwarding-for-global-administrator-accounts
I hope this helps to resolve your query. Please "Accept the answer" if the information helped you. This will help us and others in the community as well.