You implement split tunneling through routing. The VPN client receives a list of networks to send through the tunnel.
Example: Your internal networks are and . Push these routes to VPN clients. Traffic to those destinations enters the tunnel. Traffic to (Google DNS) goes directly to the internet.
Some organizations use inverse split tunneling. They push a default route through the VPN but exclude specific cloud services like Microsoft or Zoom.