@PhilipDAth Is correct in that with MX autoVPN, currently you have to full-tunnel all client traffic or split-tunnel for all!
@SoCalRacer's suggestion to use Client VPN for those clients is also very clever and is viable (if it's only 2 clients, but might not scale if this number increases)!
If you throw Meraki access points in the mix, you can look into SSID Tunneling! This allows any clients connecting to the configured SSID to full-tunnel (or split-tunnel) their traffic to a MX concentrator.
If this was helpful, click the Kudos button below.
Please mark it as a solution if solved your issue so others can benefit from it 🙂