@Ryan Kielar Thank you for reaching out to us, As I understand you are hesitant to enable it as it shows it shows Object scope filters set to "All users" even though you configure a particular OU to sync.
Tested the same scenario in my lab, below is the configuration
When you sync the user (which is not present in above mentioned OU), then during provisioning below is the operation which we see (scoping filter evaluation passed will be false) for the user not present in that OU.
Rest assure, though it says object scope filters is All users, if you have configured the specific OU in the configuration, only the users part of that OU will be synced.
Same has been documented here as well - https://learn.microsoft.com/en-us/entra/identity/hybrid/cloud-sync/how-to-configure
Let me know if you have any further questions, feel free to post back.
Please remember to "Accept Answer" if answer helped, so that others in the community facing similar issues can easily find the solution.