Do you mean that after removing user_Cookies your delta Aggregation is working or Full Aggregation is working, as per connector document below are the permissions required:
Please note that the first time this delta aggregation task runs, it will perform a full aggregation. This is because the DirSync aggregation process relies on a cookie (provided by AD and stored in IdentityIQ) to determine which records to provide. When the task is run for the first time, the cookie is null so there is no basis for identifying which records to pull and which to ignore. After the delta aggregation task runs, the cookie value is provided to IdentityIQ by AD and is stored in the AD application definition inside IdentityIQ to use in the next delta aggregation. Subsequent delta aggregation runs will retrieve only records which have changed since the last delta aggregation, based on that cookie, and the cookie is updated at the end of each delta aggregation. Separate cookies are stored for accounts and for groups, and separate cookies are stored for each domain as well.