@Charlie-9453 Reviewed the configuration, found you had a custom sync rule created to stop syncing disabling accounts from on-premise to Microsoft Entra portal. Followed the steps mentioned here - https://spanougakis.wordpress.com/2016/02/28/how-to-stop-disabled-user-accounts-from-syncing-with-azure-ad-connect/ deleted the existing rule and re-created again, which helped to remove the disabled accounts.
Later there was another issue reported where admin accounts which were disabled (UserAccountControl having value 514) custom sync rule not getting applied on those account, on further research found this all started after upgrade to latest version, for time being we modified the sync with the below values
UserAccountControl EQUALS 514
UserAccountControl EQUALS 66050
UserAccountControl ISBITSET 2
Reference: https://jackstromberg.com/2013/01/useraccountcontrol-attributeflag-values/
After making the changes, ran the full sync and verified the issue, disabled accounts have been removed from the portal as expected.
Let me know if you have any further questions, feel free to post back.
Please remember to "Accept Answer" if answer helped, so that others in the community facing similar issues can easily find the solution.