Explanation Trust configurations - Configure trust from managed forests(s) or domain(s) to the administrative forest * A one-way trust is required from production environment to the admin forest. * Selective authentication should be used to restrict accounts in the admin forest to only logging on to the appropriate production hosts. References: https://docs.microsoft.com/en-us/windows-server/identity/securing-privileged-access/securing-privileged-access-