The client blindly passes the Service Provider portion of the Service Ticket to the Service Provider in the TGS Exchange to establish a client/server session.
If Mutual Authentication is enabled, the target Service Provider returns a timestamp encrypted using the Service Ticket TGS Session Key. If the timestamp can be decrypts correctly, not only has the client authenticated himself to the server, but the Service Provider also has authenticated to the client. The target Service Provider never has to directly communicate with the KDC in the Client-Server Exchange.