You have three users who travel to four branch offices often and need to log on to the RODCs at these offices. The branch offices are connected to the main office with slow WAN links. You don't want domain controllers at the main office to authenticate these three users when they log on at the branch offices. What should you do that requires the least administrative effort yet adheres to best practices?