You don't have to add them to the domain - you can leverage the Windows "Workgroup Authentication" (there may be a more official name for it, that's what I know it as) where you create local accounts on the app tier with the same user/pass as a local account on the box they're connecting from.
You can see AdamSinger's recent post about this (although his is more focused on not having AD around at all)
http://blogs.msdn.com/adamsinger/archive/2006/09/22/766187.aspx
Also, this article has a relevant section ("Team Foundation Clients in a Workgroup and Team Foundation Server in a Domain")
http://blogs.msdn.com/vstsue/articles/Managing_Team_Foundation_Server_in_a_Workgroup.aspx
Team Foundation Server - http://blogs.msdn.com/jmanning/ |