For example, in our /etc/datasync/configengine/configengine.xml the admins dn blocks are before the block.
<ldap>
<groupContainer>o=tt</groupContainer>
<secure>true</secure>
<hostname>ldap.tt.nl</hostname>
<enabled>true</enabled>
<admins>
<dn>cn=admin,o=tt</dn>
<dn>cn=piet,ou=users,o=tt</dn>
</admins>
<userContainer>o=tt</userContainer>
<login>
<dn>cn=LDAP_User_Locator,ou=sys,ou=alg,o=tt</dn>
<protected>1</protected>
<password>VTJGc2RHVmtYMStkcBLABLABLABLABLABBLABLABLA=</password>
</login>
<pollInterval>300</pollInterval>
<port>636</port>
</ldap>