Thanks for posting in Microsoft MECM Q&A forum.
1.Agree with Jason. Extending the schema is a one-time action for any forest, there is no need to do it in the child domains too. To verify whether AD schema extension was successful, open the log file extadsch.log located in the root of the system drive. Please also make sure that the primary site or CAS server computer account have been granted Full Control permissions to the System Management container and all its child objects to publish site information to the container.
For more information, please refer to: Installing Prerequisites for Configuration Manager
2.Active Directory Forest Discovery accout could be the computer account of the site server or a user defined Windows user account. This account must have Read permissions to each Active Directory forest where you want to discover network infrastructure. And also this account must have Full Control permissions to the System Management container and all its child objects in each Active Directory forest where you want to publish site data.
For more information, please refer to the official article: Active Directory forest account
If the response is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.