Hello Tristan Coopman,
As per description, we understand that a single user is not getting deleted even when you remove the user from user provisioning group.
Please let us know if the issue is only with a single user. If so, have made any changes to the attributes at the target system for this single user.
Have you changed any attributes of the effected user on the target system?
Request you to check the provisioning logs for the effected user. You can select the audit log for the effected user to show more details such as the steps taken to provision the user and tips for troubleshooting issues. The details are shown in 4 tabs.
When you access 2 tab, Troubleshooting & Recommendations you can there was an error, this tab provides the error code and reason. In many cases, a detailed description of the error is provided. Review this information to understand the issue and follow the guidance provided to resolve it.
Modified Properties: If there were changes, this tab shows the old value and the new value.
Summary: Provides an overview of what happened and identifiers for the object in the source and target systems.
Reference :
https://learn.microsoft.com/en-us/entra/identity/monitoring-health/concept-provisioning-logs
I suggest you refer below document on known issues with app provisioning
Please let us know if you have further queries.