I had already looked that stuff up. Unfortunately it doesn't work. One of the problems is that the provisioning cmdlet creates a Global Group in the target domain, then proceeds to try to put the IPAM server in that group. This has to fail as a security principle from Domain A cannot be a member of a Global Group in Domain B. I eventually worked around it by creating the group manually, and removing it from the DNS Admins Builtin Group so that it could be changed into a Domain Local Group. I could then run the cmdlet as of course a security principle from Domain A can be a member of a Domain Local group in Domain B.
It doesn't work as intended because it can't.