Why would an attacker in your intranet who's looking at your network traffic be passive? When people talk about passive attackers they're talking about the NSA/ your ISP, not someone who's hands-on-keyboard sniffing traffic.
There's virtually no reason to do encryption without authentication in your intranet.