In environments where users from Active Directory (AD) need to access Hadoop Services, set up one-way trust between Hadoop Kerberos realm and the AD (Active Directory) domain.
| ![[Important]](../common/images/admon/important.png) | Important | 
|---|---|
| Hortonworks recommends setting up one-way trust after fully configuring and testing your Kerberized Hadoop Cluster. | 


