You can consider cloud management gateway solution to manage the internet connected or VPN (poor) devices https://learn.microsoft.com/en-us/mem/configmgr/osd/deploy-use/deploy-task-sequence-over-internet
Some references
https://learn.microsoft.com/en-us/mem/configmgr/core/clients/manage/cmg/plan-cloud-management-gateway
https://techcommunity.microsoft.com/t5/configuration-manager-blog/managing-remote-machines-with-cloud-management-gateway-in/ba-p/1233895
https://www.niallbrady.com/2020/06/13/how-can-i-calculate-the-cost-of-osd-content-coming-from-my-cmg/
Regards,
Eswar
www.eskonr.com
If the response is helpful, please click "Accept Answer" and upvote it.