How to Configure Entra ID Connect with Unreachable Domain Controllers and Preferred DCs

How to Configure Entra ID Connect with Unreachable Domain Controllers

For some organizations, all domain controllers may not be reachable by standard servers. Maybe they are in remote offices, on slow WLAN links, or on a ship in the middle of the ocean. One of the steps that Entra ID Connect does when you first configure it is checking to make sure it can reach all of your domain controllers. This can be a problem if they are reachable.

This blog will address a quick way to solve this problem. Note that this is a temporary workaround that should be used only while configuring Entra ID connect. Once it’s configured, you should remove the items in this blog.

This process will use the host file on the server to direct traffic bound for unreachable DCs to DCs that are reachable.

Configuring Entra ID Connect with Unreachable Domain Controllers

Follow these steps to modify the host file to redirect traffic bound for unreachable DCs. These steps are performed on the server running Entra ID Connect.

  1. Run Notepad as administrator.
  2. Open the file C:\Windows\system32\drivers\etc\hosts. Note that hosts have no file extension, so you may need to change the File Type to All Files (*.*).
  3. At the bottom of the host file, add the IP of a reachable DC, press tab to tab over, then add the hostname of the unreachable DC, like this:
<reachable DC IP> <unreachable DC host name>
192.168.1.3 PacificOceanDc1.contoso.com

Add all your unreachable DCs to the host file on separate lines.

  1. Save the file. Note, if you get a permissions error when saving, be sure that you launched Notepad as administrator.

Once Entra ID Connect is installed, repeat steps 1-4, but remove the added lines to the host file. You can also comment them out by putting a “#” at the beginning of the line.

Entra ID Connect Preferred Domain Controllers

Now that we’ve been able to get Entra ID Connect installed with unreachable domain controllers, we need to make sure that Entra ID Connect doesn’t try to use them in the future. Entra ID Connect should only connect to DCs within its AD site. You can use this procedure to make sure of this.

  1. From the server running Entra ID Connect, launch the Synchronization Service application.
  2. Click Connectors in the ribbon and select the connector with type Active Directory Domain Services.

  1. Right-click and select Properties.
  2. In the left pane, select Configure Directory Partitions.
  3. Check the box for Only user-preferred domain controllers. This should launch the Configure Preferred DCs box. If not, click the Configure button.
  4. Type the name of the DC you want in the list and click Add. Do this for each DC.
  5. You can reorder the list using the Up and Down buttons.
  6. Click ok and save your changes.

Final Thoughts

For large and geographically dispersed organizations, getting Entra ID Connect installed may be a challenge if all DCs are not reachable by the Entra ID Connect server. Hopefully this post helps you get Entra ID Connect installed and working. If you need assistance, please contact WME and reference this blog post.

Why Choose WME for Entra ID Expertise?

At Windows Management Experts (WME), we offer professional Entra ID solutions highly customized to your unique needs. Our certified Entra ID professionals specialize in the seamless deployment, configuration, migration to Entra ID and whatnot. They’ll cetainly ensure your systems operate at peak performance without any disruptions.

Our Entra ID Services Include:

  • Comprehensive Entra ID Migration:
  • Entra ID Connect Configuration
  • Managed Services & Optimization
  • Entra ID Security & Compliance

No matter if you are starting fresh with Entra ID or migrating from another platform, our team is here to ensure a smooth transition for you.

Contact us today to learn more about Entra ID migration and configuration needs!

 

Disclaimer

All content provided on this blog is for information purposes only. Windows Management Experts, Inc. makes no representation as tothe accuracy or completeness of any information on this site. Windows Management Experts, Inc. will not be liable for any errors or omissions in this information nor for the availability of this information. It is highly recommended that you consult one of our technical consultants, should you need any further assistance.

Windows Management Experts

Now A Microsoft Solutions Partner for:

✓ Data & AI

✓ Digital and App Innovation

✓ Infrastructure

✓ Security

The Solutions Partner badge highlights WME’s excellence and commitment. Microsoft’s thorough evaluation ensures we’re skilled, deliver successful projects, and prioritize security over everything. This positions WME in a global tech community, ready to innovate on the cloud for your evolving business needs.

Contact us: sales@winmgmtexperts.com

Share:

Facebook
Twitter
LinkedIn
Picture of Andrew Sanders

Andrew Sanders

Contact Us

=
On Key

More Posts

WME Cybersecurity Briefings No. 037
Cyber Security

WME Security Briefing 06 January 2025

Evolving Strategies for Managing Expanding Attack Surfaces Overview As remote work gained incredible traction and an already-existing digital transformation accelerated, the domain of attack surface management, as previously understood, has changed profoundly. Modern infrastructures are normally spread over

Click Here to Read Full Article »
Be assured of everything

Get WME Services

Stay ahead of the competition with our Professional IT offerings.

=