He wouldn't be logging into the domain mass, thats the whole point, he would be logging in as the local ***** and the domain polocies(If not set otherwise) shouldn't block his access. I understand when you say the wireless would be on the hardline but it definitely check's with with an ACL before it lets you have access,(If it's using a NAC) It's installed at my college, and yes it is on a separate subnet from the physical lan. On a Catalyst 2600 you can set each port to whatever subnet you want if you wanted to do so, to keep 2 networks seperate. Most expensive hardware has this ability, but I've only experienced a brief use of Cisco's hardware, and it's definitely the way to go for security.
If he doesn't have this in place then none of this even matters to him, but I just want to make sure I am explaining myself clear. I put together a little topology pic so you can understand visually.
