It's now possible to update on-premises synced users via the Microsoft Graph API using API-driven inbound provisioning:
https://learn.microsoft.com/en-us/entra/identity/app-provisioning/inbound-provisioning-api-concepts