You need to ensure that domain controllers in the spoke sites can replicate with domain controllers in only the hub sites
You need to implement a GPO management strategy to ensure that the administrators can access the .admx files and any future updates to the .admx files from each office