Thanks for all of your responses, sorry I could not answer any sooner. I will answer your questions below.
There have been several hotfixes for AD Import; are you running any of those?
I just applied KB34704 AD Connector update. Of several things this update was going to fix the problem of AD Import failing after a previously know OU was missing during the LDAP query. I created the test OU and fake computer account to test this behavior but I have now been sidetracked with this issue. I plan on applying Rollup 13 in a few days.
What results do you get with "real" computer objects, which are tied to a managed machine?
That is mixed and is why I applied this update. Previously I have had several (230 or so) AD Imported computers (1800 total computers) set to “Retired” by the NS as opposed to being deleted by Directory Sync and are not being purged because they are Retired.
If you watch the NS logviewer while the Directory Resync process runs, does it remove the computer?
The logviewer appears to show Directory Resync working. The only errors associated with Directory Resync are with deleting a collection that says it has dependencies but none are present. If I look in the ItemReference table it has an entry with a ReferenceType=0 to a collection that in the item table shows ProductUninstalled=0. I searched the entire NS for that collection and I cannot find it. Should I delete that entry from the ItemReference table? Could this hold up the processing of the rest Directory Resync, it hangs on that error?
Also, are you pointing to the domain in general (ad.mycompany.com) or a particular DC?
This is a 2003 domain and I’m pointing to a particular server, I know the redundancy is better to a domain but I feel I get better results this way. I always do Full Imports on computer objects.
Can you specify OS information about a "dummy" object like this when you create it?
It appears not.
Can you try the same behavior with a REAL account (meaning the associated computer has logged onto AD)?
I’m trying too but the only computer I could test with was a managed computer, so I removed the agent using the NS Console however the computer is still showing as IsManaged=1 and I don’t have access to it anymore. Long story…busy IT shop. If I could manually force IsManaged=0 like you can force Unmanaged Mode in ForeFront I would be set.