Per user authentication (such as AD Authentication) allows the user of WPA2-Enterprise mode, which generates per-user keys. It is far superior to everyone using the same pre-shared key.
Take the simple task of administration. If one person leaves, you disable their AD account and they can no longer access WiFi. If you are using a pre-shared key they can either continue to access the network, or you have to change the pre-shared key on the WiFi network and every single device that connects to it.