Modify the user's security role to include the missing privilege. When you click the Details section, it should include the name of the missing privilege. In the example below, the user is missing the read privilege for the Email Server Profile entity.
T:331ActivityId: <GUID>>Exception : Unhandled Exception: Microsoft.Crm.Asynchronous.EmailConnector.ExchangeSyncException: Failed to update the sync state : Unhandled Exception: System.ServiceModel.FaultException`1[[Microsoft.Xrm.Sdk.OrganizationServiceFault, Microsoft.Xrm.Sdk, Version=, Culture=neutral, PublicKeyToken=31bf3856ad364e35]]: Principal user (Id=<GUID>, type=8) is missing prvReadEmailServerProfile privilege (Id=edebe6f6-cf2e-4520-b635-ae0615d41e34)Detail: f6afa1da-a317-4cfd-a3ea-cb062b28dbcf -2147220960 Principal user (Id=<GUID>, type=8) is missing prvReadEmailServerProfile privilege (Id=edebe6f6-cf2e-45...
For a list of privileges that may be required to use Server-Side Sync, refer to the More Information section.