A whole network vs. one authenticated laptop.
Using Site-to-Site VPN for a remote workforce means building your own concentrator — Client VPN already is one.
Site-to-Site VPN
IPsec tunnels, Customer Gateway → VGW/TGW. Every on-prem device reaches the VPC, no per-device config.
Client VPN
Managed OpenVPN endpoint. Individual users, AD/SAML/cert auth — the remote-access VPN equivalent.