For Windows VPN scenarios, the recommended approach is to configure split tunneling routes for the VPN connection and add the organization’s internal destination prefixes there so traffic for those subnets uses the VPN, while other traffic can use the local network.
If the VPN is managed through Intune on Windows devices:
- Open the Windows VPN profile settings in Intune.
- Go to Split Tunneling.
- Set Split tunneling to Enable.
- In Split tunneling routes for this VPN connection, add each internal subnet as a route by entering:
- the destination prefix
- the prefix size
This is the supported way to include internal IP ranges in the VPN path.
If the issue is specific to Microsoft 365 optimization, only Microsoft 365 Optimize endpoints should be excluded from the VPN path, while internal corporate subnets should remain in the VPN inclusion list. For Windows built-in VPN, this model is described as Force Tunneling with Exclusions, where defined destinations can use the physical interface and all other traffic continues through the VPN.