While the connection server should have a bi-directional trust with the user domain, this doesn't limit the individual desktop VMs - they can still be in their own domain with a one-way trust back. This isn't something that has changed, we've always called for a two-way trust - you can find the same note in the admin guides, going back several releases. From the 3.1 admin guide for example:
NOTE In order to add users in an Active Directory domain other than the one in which
you have installed a standard or replica View Connection Server, you must establish a
two‐way trust relationship between their domain and the one in which the View
Connection Server is located.