You will have to explicitly configure which Anyconnect headend the users will be connecting to.
Such as setup ion your case could look like this:
- Your users still connect to your on prem MX and will have access to your internal data
- Your on prem MX builds an automatic AutoVPN tunnel to your vMX in Azure. This way, your internal users as well as your roaming clients will be able to access resources within Azure.
This could also be working the other way around, but you'll have to keep in mind that there are possible limitations posed by Azure for outgoing traffic from your Anyconnect clients.