That's basically Kerberos, which ad is "built" on and extends. I believe both Kerberos and ad require the server to be known to the ad or Kerberos master.
In some sense that has morphed into login with Facebook/Google
Kerberos set the standard for a lot of authentication protocols and it's model of delegated authentication can be seen in the SAML and OpenId Connect protocols