vCenter 7.x
vCenter 8.x
This issue occurs when the vCenter Identity Source is configured using the root domain name instead of specific hostnames. When pointing to the root domain, vCenter queries DNS for all A records (Domain Controllers) and may randomly attempt to connect to firewalled, unreachable, or high-latency DCs, leading to authentication timeouts.
If desiring to return back to using the root domain as URL for round robin use of multiple domain controllers do the following.