Hi,
what do you mean with "policy"? On the firewall?
As I know, the configuration on the Identity Collector software is only oriented to retrieve identities from Active Directory servers, and then put them to the gateways, so I suppose the "unable to delete" message is related to the software itself, which is using the "domain" object as Identity Source.
I also tried deleting related domain controller object => same behaviour.
And, finally, there's no way to "pause" both DCs and Identity Sources for the delete operation to be permitted.