Configuring Identity Synchronization for Windows to support multiple domains involves the following:
Setting up destinationindicator <-\> activedirectorydomainname <-\> user_nt_domain_name as a synchronized attribute
Using destinationindicator in the SUL filters so that entries modified in Directory Server can be located in the proper Active Directory domain
When linking users by using the idsync resync command, specifying allowLinkingOutOfScope="true" in the input file.
Do not specify the -k option because you want the destinationindicator attribute to be primed.