Regarding preventing new AD account creation under certain circumstances

Check out the Identity Fusion Connector: Identity Fusion Connector - CoLab / SaaS Connectors - SailPoint Developer Community

It was built specifically to take identity records from multiple sources, combine them into one, and even provides a form for administrators to act on potential matches.