@probi Firstly, apologies for the delay in responding here and any inconvenience this issue may have caused.
Looking at reference designs, my understanding is that the hub vNet is treated as your un-trusted zone and then any spokes are trusted => that's true
It's based on your design and you can perform the POC test and go through. For now design isn't recommend
Hope this helps!
Kindly let us know if the above helps or you need further assistance on this issue.
Please don’t forget to "Accept the answer" wherever the information provided helps you, this can be beneficial to other community members.