Should perhaps implement a RADIUS server - the idea being that if the VPN server is compromised, the domain trust can be severed.