1. Are folks using a OD based admin account (mobile) as the local
admin account which would allow for more control in changing
passwords, etc. and not having to have the account on the image
itself?
You can do this.
You can also nest an OD group inside the local admin group, which
gives you a much more flexible way of managing administrative rights,
while still being able to audit admin access and tie it back to
specific people.
Generic admin accounts are kind of bad on clients if you care about
auditing in my opinion.