Another option is port security, but a big admin overhead. MAC addresses are defined and allowed access only on specific interfaces.
Not good in a 'hot desk' environment.
eg:
! interface FastEthernet0/2 description desktop switchport mode access switchport port-security switchport port-security aging time 2 switchport port-security violation restrict switchport port-security aging type inactivity switchport port-security mac-address sticky switchport port-security mac-address sticky 0000.3911.c3f4 mls qos cos override macro description cisco-desktop spanning-tree portfast spanning-tree bpduguard enable !
Big Si.