This youtube video well explain situation in case two forests/domains are in bidirectional trust and exchange server is in a single domain. To give ability to a single user to utilize exchange mailbox on other domain you need to take confidence with linked mailboxes concept:
This image, indeed it explain AD group differences: