Why are deprovisioned users not visible in Dynamic Groups, even if they are included explicitly?
This is by design Active Roles Server will never include deprovisioned users. If an administrator deprovisions a user and then manually enables, re-names the user, and allows the user to login, the edsvaDeprovisionStatus will still be a value of 2, indicating the account was deprovisioned.
Undo deprovisioning on the user in the Administrator Console MMC, or the Active Roles Web Interface. This will clear the value and allow the user to be listed properly in the Dynamic Group.