HiI have an environment with Cisco ISE, joined to our subsidiary Active Directory. Our AD uses multiforest design, with users in one forest owned by HQ, and resources (groups, computers, GPOs etc) in our locally managed forest (two way trust in place...