Thanks for all your replies.
Then let me ask you this... What would you do in this scenario without over complicating the new setup?
-You moved to a new internet circuit with a Meraki MX68
-Using AnyConnect VPN split-tunneling (w\RADIUS/AD Authentication) for 70 remote workers
-You have 2 developers that need to show a specific public IP to connect to a 3rd party server
Would you even entertain the idea of going with a full tunnel for all?