I think this is a case of over-thinking the issue.
From a practical standpoint, the minute you remove the PC from the domain, its domain users can no longer log on. Unless the user attempting to log on has a local PC account that should be a non-issue.