When using a Users Active Directory import within an OU, inactive users are being imported even though the User Basic Import Constraints are set to Enabled.
When the Users AD Import Rule runs, each time the import allowed for the inactive user to be imported and listed in the SMP console under the User OU types.
ITMS 8.5 RU4 and earlier
Known issue. Currently, "disabled" resources are being imported because we have "resource associations" to be created - for example, "manager" and "directReports" property of the user entry in AD will bring in associated user resources, even if they are disabled.
It has been fixed, filters will be applied to associates, which have the same resource type, as the original rule resource (user/computer etc.)
This issue has been reported to the Symantec Development team. A fix has been added to our next release: ITMS 8.6.