@McMaster, John, Thanks for posting in Q&A. Based as I know, Hybrid Azure AD join devices needs to use domain user credential to access. For Azure AD joined device, it uses Azure AD user credential to access which can be on the Internet.
For the users need to work at home, you can consider Azure AD join when create Azure Network Connection for Windows 365.
Hope the above information can help.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.