I have not had these issues on 10.0 upgrades, but have experienced similar issues in 9.0/9.1 upgrades.
For you ldap pending users missing issue - where are those supposed to come from? Is the Upgrade Manager responsible to move them, another utility or a manual process? Those have been moved manually in upgrades I've done in the past. Be sure you know precisely the step they are missed on and look in the logs to see if there is a reason for failure if it is indeed a programatic failure.
For the missing columns, and default values, I have had similar issues on previous upgrades, the columns should be added during a upgrade step like 'upgrade schema'. You should see failures in the logs, they will be helpful to uncover why the columns were not addeds.
In my experience it is not dangerous to proceed with manual fixes in upgrade rehearsals, but I prefer patches before production to be used on my penultimate upgrade rehrearsal to make sure they are good (if in fact patches are the fix).
/pete