Central vs Local authentication is a "per WLAN" configuration, so a single WLAN cannot have APs doing both central and local "authentication". You can keep the auth Central, and if you're FlexConnect groups are configured properly, your "remote" APs can always "failover/fallback" to using LocalAuth in the event of connectivity loss to the WLC (APs transition to standalone), but you can't explicitly force one or the other on the same WLAN.