@gjacobse said:
@travisdh1
No - User accounts are 'left' so that is connection to the AD / DC is lost, then the user can still log on.
That's not totally true, all profiles files are left, that doesn't mean you can still login to it necessarily. There's no process for AD to talk to the local computer to tell it the user was removed. It is just a directory service, The local computer has to request to login to the account. There is no method AD to tell computers anything changed without them requesting.