@fcmendoza You can also consider splitting your refresh as below, we did in our environment it’s working fine:
- Refresh 1: Refresh identity attributes, Refresh Manager Status
- Refresh 2: Process Events
- Refresh 3: Refresh assigned, detected roles and promote additional entitlements, Provision assignments & Refresh role metadata for each identity
- Refresh 4: Synchronize Attributes (this can also be clubbed with Refresh1)
- Refresh 5: With all other options that you want.
We split this considering that in case there are any delays or failures, we can directly execute the impacted task.