In workgroup mode all windows logins will require local accounts.
The specific difference between a 'workgroup' and a 'domain' is that in a domain, each workstation is re-configured (during the 'join' procedure) to 'trust' the domain controller.
The purpose of this workstation-to-server "trust" relationship is to let the domain controller tell the workstation 'yes - this user is permitted to login'.
In 'workgroup' mode, this trust relationship has never been created, so the windows computer has no reason to listen to anything the server says.