Hi,
The best practice depends on your organisations Security process, the best practice is to move the users on long term leave to a seperate OU in AD and can be either disabled or kept enabled, but keep a note in the account with the details on the account if it is disabled and the reason for that. Disabling is preferred with complete notes in the account section.
Leavers can be in another OU named with specific Leaver OU, so you will need multiple OUs to differentiate Leavers,Disabled, LongTermAbsentees etc to manage the requiements.Also you can release the licenses if the user is away for long time so you can move licenses around and save cost.
Hope this helps.
==
Please "Accept the answer" if the information helped you. This will help us and others in the community as well.