Discovered that the Active Directory to Microsoft Entra ID sync issue was caused by external DNS resolution, ultimately the root of it being incorrect DNS forwarders on all domain controllers from a legacy configuration. We have set external DNS forwarders to use going forward.