I still prefer a VPN client solution like Zscaler's ZPA, because it can identify if you're on a trusted network (your local networks in the office) and disable the VPN client automatically.
I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.
Please, if this post was useful, leave your kudos and mark it as solved.