Kerberos Ticket Granting Service TGS – order of communication steps

Microsoft describes the communication steps to receive a TGS as follows:

  1. client asks Kerberos DC for Ticket Granting Ticket
  2. client receives TGT (if authenticated successfully)
  3. client asks KDC for Ticket Granting Service, to get access to a certain platform
  4. client receives TGS (if TGT was valid)
  5. client accesses the platform and offers the TGS
  6. platform grants access (if the token is accepted)

Kerberos V Exchange TGS

I wonder how the client could ask for a certain TGS in the first place before the user hasn’t even tried to access the destination platform? Or is this user step just omitted in the above given illustration?