From the MS blog post:

>Users with AD credentials can request tickets to any service account in AD.

I assume it means you can derive the service password to leapfrog up the chain to wherever you want to go.