In my on-premises SharePoint 2013 farm I have configured another domain as a two-way non transitive trust. I'm using the SharePoint farm to host PowerPoivot workbooks with BISM connections to an analysis services (same domain where I hosted my SharePoint).
Observations : Users from my primary domain can refresh workbooks, but users in external domain cannot refresh. The error is "SPSecurityContext: Could not retrieve a valid windows identity for username 'DOMAINB\test' with UPN 'firstname.lastname@example.org'. UPN is required when Kerberos constrained delegation is used"
I did following checks
Service users (claims to token service and excel services) is available in local "WSS_WPG" group