It's because he wants to check for a user other then the one that is currently logged on (not sure why). That requires a more in depth check using LDAP.