Personally I run the VPN in a VM on my private device and I would recommend to do that to everyone. You have a VPN without split tunneling within the VM, it is containerized from your other OS and separates work and leisure and you can use your normal WAN connection to access the internet at full speed.
With how verbose and talkative applications today are it wouldn't be appropriate to route their traffic through the company line anyway.
Of course that decreases the security that deactivating split tunneling offers to a degree, but I think we have to live with that. All this security is ineffective anyway if 99% of attacks come through the inbox. That will never be change and people need to be educated and have to trust IT that they don't blame the user since it can happen to everyone and nobody is on guard to 100%. With decent backups the damage can usually be completely mitigated without a lot of expensive security measures.