Stich,
For what it is worth, my guess would be this:
1) Workstation has to be in the domain, not workgroup.
2) When you log in with the workstation you need to do so via "dial-up networking" using the vpn connection.
It is easiest, or at least used to be, to put the workstation in the domain while it is on the same physical LAN, not using VPN, if this is possible. Not sure if Linux really cares, but NT sure like it better.
/B