A remote workforce uses split-tunnel VPN to reduce bandwidth costs. The security team discovers employees are accessing sanctioned SaaS applications directly from home networks, bypassing the corporate proxy and DLP controls. Management values the current performance gains. What is the MOST appropriate recommendation?
A. Switch to full-tunnel VPN to route all traffic through corporate controls
B. Deploy a cloud-based secure web gateway to enforce policy at the endpoint
C. Accept the risk and document the DLP gap as a known exception
D. Restrict SaaS access to corporate-managed devices only