No we don't want to use Full Tunnel mode, but documentation says you have to use Full Tunnel mode on a vMX in Azure if you also want to use Routed mode (because the vMX won't advertise subnets). Routed mode is required because the vMX is replacing a competitor vendor equivalent which is doing NATing.
Local breakout is an option we hadn't considered, but that doesn't require SD-WAN plus I thought?
The other workaround we were considering would be to put the vMX in a separate org and configure non-Meraki VPN.