I'm not convinced that is really true. Sure, some sort of client authentication is technically required, but I think you can configure the authentication server to accept any authentication without compromising the link security. Or you could auto-provision users on first login or something like that depending on what sort of access you want to give.