The user must exist as a login on both sides (unless your in contained database territory)
You then also need to ensure your licensed correctly, as allowing a user access to the secondaries to run queries is classed as production use and now the secondary MUST be licensed accordingly.
You then configure readable secondaries, plenty of information on this on a Google/Bing search.