For just two machines, I would not bind them to AD, just create a generic log in and then connect to their shares from the GO menu in the finder. This way you can limit rthe local user, so they cannot use other apps (although Macs are excellent at restricting software installs by their native UNIX core). We found binding to AD using Mac OS X 10.4 creates a number of rogue files on the network.
We now use ADMITMAC on a school network of both PCs and Macs, with an XSERVE for locking systems down to pupils - which works well and is cost effective if you use more than 20 macs.