Eventually, since active directory truncate long user names within sam account name, we must use user principal name and consult gc (lower performance).
Posting original request: RHEV-M should be able to query the GC for user information. Functional Requirements That Are Not Presently Possible: Consider the case where one has two AD domains A and B. Between these domains, there is a trust relationship such that B trusts A. It is currently not possible to authenticate users present in A without directly connecting to A. Currently it _is_ possible to configure RHEV-M to use several AD:s but that requires that RHEV-M should be able to connect directly to all of them. If a firewall is preventing this, users from A can not be used although there is a trust between them.
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHEA-2015-0174.html