In your case, I would use Azure Migrate, https://learn.microsoft.com/en-us/azure/migrate/migrate-services-overview.
You create a process server on your on-premises infrastructure and this server has access to the internet. This server must have communication with the Root Server. Yes, you must have online access during the replication.
Hope this helps!
Remember to accept the answer if it is helpful.