The lock feature of ThinOS just locks the thin client. The session in the background remains connected to the client. You could always diable the lock feature, set the clients to disconnect from the session and log out from ThinOS if idle for too long. That would force the user to reauthenticate to the broker/AD if you are concerned about security.