I previously worked for a remote only company with similar roadblocks. The best option I found was to have the Macs shipped directly to a tech to be configured on their network (with their network profile configured in pre enrollment for ease of use) then ship it to the end user afterwards. The end users liked the “white glove” service.
I worked for many years in endpoint management and actually like Macs. They’re not difficult to manage once you get the hang of it. In this oddly specific scenario, though, Windows would definitely be easier because the users could just login with their 365 account for provisioning.
I loved seeing models like this in science book as a kid because I’d imagine them as tiny little worlds