We achieved success after enabling split tunnel for both VPN groups you created also on the tunnel mode and full mode sections.
After that we were able to connect to the VPN with different users and have access to the internal network wihout loosing access to the internet.
Hardening:
https://docs.fortinet.com/document/fortigate/7.4.0/best-practices/555436/hardening
Security best practices
Policies
https://docs.fortinet.com/document/fortigate/7.4.0/best-practices/862226/policies
Regarding training:
- Basic - https://training.fortinet.com/local/staticpage/view.php?page=library_fortigate-operator
- Advanced - https://training.fortinet.com/local/staticpage/view.php?page=library_enterprise-firewall
- All available courses - https://training.fortinet.com/course/index.php