Internet Access only on VPN

New Contributor III

Hi Guys,

We have some requirement to limit Internet access when users are not at the office.
The way for users to use the internet would be that they connect via VPN and then they can use internet and their traffic will be monitored / routed.
For VPN solution we are using Cisco AnyConnect with user certificate and username/password.

Currently this users have set up 2 locations in Network preferences:
1. External network (which are users using while they are at home)
2. Internal network (using while in the office which applies proxy settings)

Not very familiar with proxy settings and Network Locations so I'm not sure on how to exactly approach this issue.
What would be the best solution to limit users so they have to connect via VPN to access Internet?