@Enterprise Architect, Thanks for posting in Q&A. For your situation to deploy Autopilot Hybrid Azure AD join not in office, you can use VPN. The VPN connection either needs to be automatically established (e.g. “always on”) or it needs to be one that the user can manually initiate from the Windows logon screen.
And the needed VPN configuration needs to be applied during device ESP.
Here is a link with more details for your reference:
Note: Non-Microsoft link, just for the reference.
Hope it can help.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.