If APs are remote (such is in different country, for example) and vSZ is local on same network with Radius server, it makes a lot of sense. Communication from AP is transported securely over tunnel to vSZ, and it accesses Radius, it's much more stable and secure setup.
Also, on big network number of AP may be more than number of connections Radius server supports.