Depends....
We use different organizations, in one wach of the MXs is a Hub (No autoVPN possible)
In another org we use a MX250 as a Hub and all MX 65 as spokes (but all die their own ipsec tunnel to the fortigate peer)
All designed as mentioned from the Meraki SE recommendation