In environments where users from Active Directory (AD) need to access Hadoop Services, set up one-way trust between Hadoop Kerberos realm and the AD (Active Directory) domain.
![]() | Important |
|---|---|
Hortonworks recommends setting up one-way trust after fully configuring and testing your Kerberized Hadoop Cluster. |

![[Important]](../common/images/admon/important.png)
