If these Kiosks are allowing users to get into your portal you most
likely have something like ALL NT Authneticated Users added to
contributor for the "area" that you are talking about. This is a
really bad practice as your probably seeing. Try and gain access to
one of these kiosks and see what username and machine name they are
using. This is most likely your problem.
It sounds like you might need to revise how your active directory
structure is setup and move all active employees into a specific
group. Then remove the all nt authenticated users from sites
(portal and WSSS) and replace with the AD group for active employees.