I have to say I haven't tried DSfW myself yet, just being trying to figure out if it would work in the following scenario.

I have got a client using eDir and now they have an access to the corp AD but only to a single Read Only DC. That obviously limits what they can do, but e.g. LDAP authentication against that DC works. I am wondering if I could use those AD user accounts to manage access to their local resources governed by eDir, e.g. allow them to login, map drives based on their membership in AD, etc.

I have read through DSfW system requirements but could not see what kind of access to AD is required to install DSfW. I'd imagine I'd need more than RODC and maybe DSfW isn't going to help me with what I want to achieve anyway ?