Yes, I know this and agree, using pwdLastSet is a much more reliable indication of an orphaned account.