Hello,
I see that you did a lot of research and work, congratulations on that. I don't have good news:
You require to have access to the AD DS to accomplish the hybrid Joined status. You cannot bypass the pre-check :-(
Unfortunately, you require to connect to the AD DS, the best way is via VPN or the device will be on your premises for the process.
Also, you can create a GPO on your AD DS to run the script automatically.
Hope this helps.
Please accept the answer if it helps.