why don't you use Domain auth?
otherwise you need find a way to get a kerberos ticket some how.
As I wrote "I try to figure out configuration which will be flexible."
But I stay with Domain auth.
it's not really a matter of flexibility - if you don't have a kerberos ticket you can't use ADK. typically you need the workstation to be a domain member to get a kerberos ticket if it's windows, though there could be other ways to do this. if users are going to be loging in from non-domain workstations domain auth would probably be easier to manage.