I thought it was being used for authenticating our switches so you and logon with your AD user ID, but I have one switch that was pointed to a non existant radius server and you could still login with your AD ID. Then I removed all references to anything to do with radius on another switch and could still login using my AD account. Then I took an access point out of the radius client list, and the radius references on the switch it was connected too and everything still worked just fine