I could suggest setting the laptop up so that it auto-logs on with a local
user-account. In this case the user need not know the local password so long
as it's non-expiring. (or you can make it a shared common password) They then
connect to the domain with a 'real' password once the VPN is connected.
Advantage is that Admins are free to change this password as required, and no
changes are needed on the laptop, other than the user knowing about the new
password.
At the risk of being accused of peddling my wares <g> MyLogon handles this
kind of situation nicely. The documentation explains how to set it up to
activate a VPN connection as part of the logon process.
http://mylogon.net