In order for IRM to work with AD RMS on word documents, do clients need to be added into the domain?
From my testing, this seems self defeating. If I use SP IRM and grant a user view access, if they are on the domain the RMS policy takes effect and applies the appropriate restrictions. Yet, because I have given rights via SP, the user can access the document from any machine since the document library only request the appropriate authentication. Afterward the user can open the document as normal.
I would like to know if its possible to make the document completely restricted if the user is not joined on the domain or am I not configuring something correctly.
Yes, the user needs to be a member of the domain and in addition have an RMS license assigned to them. You can do RMS federation, as well.
http://technet.microsoft.com/en-us/library/ee256071(v=WS.10).aspx