At one point AD Connect sent all users. I now have AD Connect sending very specific OUs (Devices, Groups, and Current Users). I can't get the old users in Azure AD (ones in unsynced OUs) to go away. I ran `Remove-MsolUser –UserPrincipalName John.Smith@Contoso.com` to remove them and it did... but now they're back and I don't know why.
The OUs where syncing is set up for are very limited.