They have it all, Palmer.
As far as logging in, it doesn't matter if they require a domain login or not (I decided not to use domain login since I didn't need it). That's because the stores with the private keys are protected with a user's master key that the domain admins cannot access.
On government networks that I am familiar with, they use almost all Windows and domain logins with double encryption of the master key. Here's a doc explaining the implications: https://eca.orc.com/wp-content/uploads/ECA_Docs/IE_Instructions/Password_Tips.pdf Read "Seventh".