DSA does not mailbox-enable some of the target accounts while the correct options were set on the Specify Exchange options tab of the synchronziatio.
Problem users are present in the failed objects list with password or sid history errors, for example:
Error 0x8007052d. Unable to update the password. The value provided for the new password does not meet the length, complexity, or history requirement of the domain.
This behavior is by design.
There should be no errors when creating the target user or synchronizing their password and setting sidhistory, otherwise directory sync will stop working on the user before reaching the mailbox-enabling stage.
The issue causing the object to appear in "Failed Objects" list should be resolved first. For the example above the soution would be reseting the source password to a value that was never used before and would not be present in password history.
For further information on the process to mailbox-enable target user accounts please see: https://support.quest.com/Search/SolutionDetail.aspx?id=SOL24845&category=Solutions