We tried the disabling the accounts and still cannot get that one single user to appear in alfresco. If we have them log in using <em>username@domain</em> they can log in with their credentials, but alfresco creates a new user for them and does not retrieve the user details. If we add them to the AD group in alfresco, they get dropped out of the group when alfresco re-syncs with AD, so we had to create a local alfresco group with the same permissions as the AD group that is synched to Alfresco.
I have not tried to disable Alfresco's create missing person functionality yet as I can find any documentation on how that will affect us adding new users to an AD group and have it sync with Alfresco.