The following error may appear under synchronization when selecting "Failed Objects", and in the dsa.log:
LDAP error 0x35. Unwilling To Perform (0000052D: SvcErr: DSID-031A0FC0, problem 5003 (WILL_NOT_PERFORM), data 0).
0x0000052D ERROR_PASSWORD_RESTRICTION "Unable to update the password. The value provided for the new password does not meet the length, complexity, or history requirements of the domain."
This issue can occur if the synchronization of passwords is not selected, and the target object will then attempt to be created with a blank password, thus the DSA fails to enable the target account.
Reset the password on the target object mentioned in the error, or select to synchronize the passwords ensuring they are not blank on the source.
You can also set the target PwdLastSet=0 after modifying the GPO password policy and then remigrate the users.