ldapjs's `timeout` option is a single flat deadline for the whole operation (set once when the request is sent, not reset per entry received) — 5s is fine for a bind or a single-match search during login, but the admin "import accounts" browse runs an unbounded (objectClass=person) search across the entire base DN, which can take longer than 5s against a real AD domain and was getting killed mid-stream (surfaced as ldapjs's generic "<id> closed" ConnectionError). Bumped that one call site to 30s; login-path calls keep the tighter 5s deadline. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012o9j9RezxbZVKQMrB7oRLY