I replied to this, but it must have gotten lost in the migration? I think you probably got your answer via other means, but here's my response.
MCP stands up when it can reach the proxy, but will stand down if you have "corporate network detection" enabled.
If you have a resource or "landmark" that is reachable only when you are in the corporate network (versus VPN), then MCP will stand down in the corporate network, but stand up when connected to VPN.
This landmark could be a random port on some server or the MWG, you can use network protection to block VPN users from accessing that port.
Let me know if this makes sense.