Hi lain_chengda,
It should be the default behavior. You could refer to the following to find the details about “Log On To”:
Log On To — Click to specify workstation logon restrictions that will allow this user to log on only to specified computers in the domain. By default, a user is able to log on at any workstation computer that is joined to the domain. Note that this control
does not affect the user’s ability to log on locally to a computer using a local computer account instead of a domain account.
More details about Log On To you could refer to the following blog:
https://ravingroo.com/267/active-directory-user-workstation-logon-restriction/
As it defined that it only allows this user to log on only to specified computers in the domain, and the Mobiles aren’t in the domain, when you try to login the Mobile, it will fail.
Best Regard,
Evan