As we migrated from HAADJ devices to AADJ devices we moved to CloudLAPS and fully replaced the on-prem solution.
However the previously managed account (not builtin) could not be updated with this error:
CloudLAPS: Forbidden, password was not allowed to be updated
Removing the -UserMayNotChangePassword option remediated the problem.