S2s + AD + shared group

I have 3 servers configured to authenticate users against Active Directory base. As follow:

domain1.local

domain2.local

domain3.local

Each domains above have an openfire server to manage the users.

My doubt: - Can I share the groups of domain1.local with domain2.local vice-versa?

I need to have users from domain1 in the roster of domain2.local and domain3.local as well.

Any suggestion? I really need that…

How does “server to server” work?