Move AD Account that's already disabled to different OU

I might be wrong here but wouln’t the easiest way be to use the AC_NewParent and AC_NewName in the /provisioning-policy/UPDATE API for your AD Source with a lookup table to sort different OU’s depending on Lifecycle state and thereafter change DN accordingly hence triggering an OU move for the identity.