A family of System Center products that provide infrastructure monitoring, help ensure the predictable performance and availability of vital applications, and offer comprehensive monitoring for datacenters and cloud, both private and public.
@Ahmed Essam , If we can deploy Forest Trust with two-way direction, That means users in one forest can access resource in any domain in the other forst. We can see more details about forest trust in the following link:
https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2003/cc773178(v=ws.10)#forest-trusts
For the authentication using kerberos between the agents in any domain of one forest and SCOM server in another forest can be routed. We can see more details in the following link:
https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2003/cc773178(v=ws.10)#kerberos-based-processing-of-authentication-requests-over-forest-trusts
However, if trust can be not built, to monitor the agent in an untrusted domain, certificate is needed for the authentication. For this situation, Gateway server is recommended to be used for agent management of computers that are outside the Kerberos trust boundary of management group. We can see more details in the following link:
https://learn.microsoft.com/en-us/system-center/scom/deploy-install-gateway-server?view=sc-om-2019
Hope it can help.
If the response is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.