Currently the User Scope does not automatically update based on Active Directory deletions. If an OU/group is removed from Active Directory it is still referenced as being in scope in Password Manager.
The following has been logged as Enhancement Request ID# 84786, and has been created to add this functionality above.
Option 1: Use Active Directory Users and Computers to delete user object profiles that are not longer active.
Option 2: Add the user objects to be removed to a Group, or Organizational Unit, and exclude it explicitly from the User scope
The product team will evaluate the request and this feature may become available on a future release of the product.
Contact your Account Manager for status updates, and reference Enhancement Request ID: 84786.