No, there is no two way sync for an account enabled or disabled status like that.
If you want to writeback and sync passwords and password changes, you can do that:
How do I get Actions such as disabling an account to sync back to on-prem AD from Azure AD

I have a newly created tenant which as was synd using express settings for ADDConnect. If we disable an account in Azure AD it doesn't get synced back to on-prem?
Do we need to change something in ADDConnect to achieve this for actions like this taken in Azure AD?
-
Andy David - MVP 121.3K Reputation points MVP
2022-11-02T18:24:31.617+00:00
3 additional answers
Sort by: Most helpful
-
Andy David - MVP 121.3K Reputation points MVP
2022-11-02T17:09:24.253+00:00 AADConnect is a one-way sync with some attributes written back to on-prem.
The account must be disabled on-prem and that is synced to Azure, not the other way around. If you disable only in Azure, it will be re-enabled after the next sync if the on-prem account is still enabled.
-
David Turner 26 Reputation points
2022-11-02T18:04:23.937+00:00 Thank Andy, so do I need Federation in place then or pass-thru to achieve 2 way?
-
Guus van Berge 1 Reputation point
2022-11-21T14:25:38.757+00:00 If you have E5, and you want to achieve this due to a security risk, you can make use of Defender for Identity to disable on-prem accounts.