The idea behind orphan detection is to find accounts in your target system like AD which dont below to a user. These users either need to be linked to a real user or they need to removed. You will be able to see these in the webconsole orphan management UI.
If you want to just add these users to OpenIAM then
– disable orphan management
– disable downstream provisioning
Synch the users.