its enabled with AADConnect:
https://learn.microsoft.com/en-us/azure/active-directory/authentication/concept-sspr-writeback
https://learn.microsoft.com/en-us/azure/active-directory/authentication/tutorial-enable-sspr-writeback
If you want redundancy, you can have more than one AADConnect serve, but only one server at a time can sync with the tenant, the other server is in staging mode but can easily be switched if necessary.