By default, the K2 service account is used to connect to other domains in a multi-domain environment. In situations wherein a separate account has to be used to query users or groups from other domains, you may specify the credentials on the corresponding entry in the [HostServer].[SecurityLabel] table inside the K2 database.
On the RoleInit column of the K2 security label, you will see a DataSource configured for each of the domains configured in K2. For example,
Adding the UserName and Password properties should allow K2 to connect to the domain under the context of this user's credentials:
DataSource Path="LDAP://DC=EXTERNALDOMAIN,DC=COM" NetBiosName="EXT" UserName="[username]" Password="[password]"