No, it is not mandatory to use the Proxy, especially for AD users. In 2.x it was required to manage LOCAL Windows users, but there has always been a separate option for AD; previously called Windows Domain Service, now called Active Directory [target connector].
In 3.1.1+ instead of the proxy for LOCAL users, you can choose to use Windows Remote. Both Windows Proxy and Windows Remote can perform the same functions, however Windows Remote does not require any agents installed on systems like the Proxy does:
Windows Remote Target Connector - CA Privileged Access Manager - 3.1.1 - CA Technologies Documentation
Active Directory Target Connector:
Active Directory Target Connector - CA Privileged Access Manager - 3.1.1 - CA Technologies Documentation
Hope this helps,
Christian Lutz
Support Engineer
CA Technologies - North America