Beginning with AD FS 2016, you have the option of using a local CP trust to integrate additional forests. The only thing that you need to know is that you will lose automatic home-realm discovery for internal users. You can only provide a custom solution to do this for you:
You can configure the scenario with the following procedure:
- Set the credentials for the service account:
$credential = Get-Credential
- Change the HostName to your domain controller, and use Port 636 if configured for a secure connection: ...