Yes. In Microsoft Entra Connect Sync, target preferred domain controllers in the Active Directory connector.
Use this path:
- Open Synchronization Service Manager.
- Go to the Connectors tab.
- Select or right-click the applicable Active Directory connector, then open Properties.
- In Connector Designer, select Configure Directory Partitions.
- Select the directory partition or domain.
- In Domain controller connection settings, enable Only use preferred domain controllers.
- Select Configure.
- Add the domain controller names that Entra Connect should use.
- Restart the Microsoft Entra ID Sync (ADSync) service to apply the change.
Best practices supported by the documentation:
- Use the same domain controller consistently while testing or making changes.
- Prefer the nearest domain controller for the affected branch office, or the domain controller that holds the PDC emulator role.
- If needed, test with different domain controllers to determine whether the timeout is isolated to one DC.
- In Active Directory Users and Computers, connect to the same domain controller used by Microsoft Entra Connect when validating password changes.
- If the Connect server cannot reliably reach all domain controllers, configuring Only use preferred domain controllers is specifically recommended.
If password writeback issues continue after targeting preferred DCs, also verify that the connector account has the required Active Directory permissions for password writeback.