Set up trust between Azure AD and local AD

You won't be able to create a trust between Azure AD and your PartnerDomain. What you probably want to do is to use DirSync (http://technet.microsoft.com/en-us/library/jj151800.aspx) to keep the two AD instances in sync. This way, youre in effect extending your PartnerDomain onto Azure AD. It's smart to deploy at least 1-2 replica domain controllers as Azure VMs so that your cloud-based services will be able to contact the domain even if the site-to-site vpn link goes down.