We are having a similar issue. Multiple forests, users from multiple domains in a full trust that need to authenticate via SSO. We’ve all migrated to O365, but are maintaining on premise domain controllers and leveraging Azure AD Connect.
I’ve change...