easiest way to do this is to manually input their DNS settings to just point to a domain controller and thats it... now, that DC can only have itself as a DNS entry as well..
Ive done it for some people in my domains and it seems to work well.
If you ultimately need to have them access certain sites, add them to their hosts file.