At the moment AD and Azure AD are two separate scans with no connection in ARM. It would be amazing if you could compare two user objects (AD and Azure) of the same person.
For example: To see stuff like "last logon timestamp" of both. When you then see that one of the two is still actively used and the other one wasn't logged on in a long time you keep them active. If both objects haven't logged in for x-amount of time you can safely deactivate them for security. Object comparison combined with automation processes in that kind of way could improve ARM.