When a client is synced from Active Directory, they are still able to edit their profile within the client portal. These field should be read-only and the client should not have the ability to edit them as they WILL prevent the syncing from happening.