On discussion with the internal team, they confirmed that this will be difficult to achieve with Entra ID domain services. The recommendation is to either switch to native EntraID join or to hybrid join.
If you have applications which are hosted within the same VNET and require local domain authentication, you will need to connect your on-premises AD to your Azure VNET using Express route or Site to Site VPN.