As of Windows Server 2012, Microsoft have added Resource Based Kerberos Constrained Delegation, which allows cross-forest constrained delegation. This enables deployments to use Single sign-on even if they have resources in multiple domains (within the same Forest), without having to install a Gateway server on the resources.
Note: In order to make use of this feature, all of your domains in the forest must run in domain functional level 2012 or higher.
This article will guide you through: