You need to ensure that the domain controllers in the branch offices only replicate to the domain controller in the main office
You need to purge the list of user accounts that were authenticated on a read-only domain controller (RODC)
You need to ensure that the support technicians can reset the passwords for the user accounts in their respective office only