With this risk we arbitrarily call it inactive when the LastLogonTimestamp is older than 6 months but the computer account is still enabled in Active Directory.
Can these accounts not be cleared up or disabled rather than creating exceptions?
As a potential fix we could create informative rules for inactive obsolete client operating systems? I think these are still worth surfacing as risks in the reports just with less or no score.