As installing Lync server requires modifying the AD forest, I've decided to make it cross-forest i.e. Lync on resource forest. It has similar concept of Linked Mailbox in Exchange i.e. disabled user account on resource forest that map to the actual user SID on user forest. To do so, I've followed this guide: User Enabling in Resource Forest
If you do not have an Exchange server on resource forest, you can simply just (on resource forest):
- Create a new disabled user account with same email address as the user.
- Copy the objectSID attribute from the User Forest account to the msRTCSIP-OriginatorSID attribute of the disabled account. You can simply do so using the "AD Users and Computers" console by enabling "Advanced Features" on the "View" menu.