Profiles are generated for all users in the forest

If you use Auto Zone, all of the profile attributes that are normally defined in the zone to which a computer is joined are generated automatically based on user attributes in Active Directory or based on a set of agent configuration parameters. By default, all Active Directory users and groups in for the forest automatically become valid users and groups on the computers joined to Auto Zone. The generated profiles have a unique UID and GID for each Active Directory user in the forest. The generated profile is what enables access to the computers joined to Auto Zone.

In addition, if you have Active Directory users in another forest that has a two-way trust relationship with the forest of the joined domain, all of those users are also valid users for the joined computer.

Auto Zone does not support one-way trusts. If a computer is joined to a domain that has a one-way trust relationship with another domain, the users and groups in the trusted domain do not become valid users and groups on the computer.