Thanks Joe. That is the way I have configured now. I have one office which they actually benefit from connecting to as there is a domain controller on prem so it is actually providing some additional AD replication.
Thanks for your help and taking the time to reply.