If you're ever in the enviable position of having to get your AWS Elastic Map Reduce (EMR) cluster authenticating against an on-prem/cross-cloud Active Directory instance this post is for you!
Let's break this down into the separate pieces we're going to need:
1.
A VPN/Direct-Connect connection to the