@mb-panketal
Something to read : 21.2.1. GSS-TSIG Overview
That's what I'm using so Kea's DDNS can communicate with a remote DNS like Microsoft AD (if I understand the doc correctly.
Not very surprising, as bind and DC are, imho, the most common ones.
So, don't wait, don't switch, don't relay, but :
4. Setup and start the Kea DDNS (see my other post).
This probably needed "Kerberos 5" stuff and looking at other "pfSense Microsoft DC" forum posts, pfSense has the needed libraries already.
So it issue might be as simple as
You want A to talk to B,
So :
Make them talk.
And I get it, this concerns a Microsoft product so finding doc is a bit hard(er) ....