I don't use AD, all users are registered in NxFilter. Sorry for my ignorance, but would NxClient serve me well in my user scenarios?
Apart from the common machines (subject of this topic) my users also shares eg. iPads which on which the web login must be used - and I'll to setup an suitable TTL for the login sessions.