When a hardware object is moved in AD to another container, in a subsqeuent sync, the membership cannot be matched because the Distinguished Name of the hardware was changed if hardware objects are not included in the sync config.
The membership will be deleted in Identity Manager as expected, but additionally in AD which is not intended.