How can I activate LDAP Syncronization changes automatically?

This is how I have set it up currently. You are correct, I am looking at the whole subtree. Would all entries one level below be correct to prevent changes like the one in my original post?

Those changes do appear not very often, maybe like once a day right now.

image