When a workstation or server attempts to authenticate a user on another domain, does the workstation or server contact the other domain's DC directly to authenticate after contacting the local domain DC? Or does the local domain DC do the authentication request on behalf of the workstation?
Example:
I currently have two domains.
Domain hosted.contoso.com and office.contoso.com.
All users are created in the office.contoso.com domain, so a user Smith@office.contoso.com wants to login to a machine host1.hosted.contoso.com. Does host1.hosted.contoso.com need to have visibility to domain-control.office.contoso.com directly?