Works for exclusions, as stated in the documentation, both in R81.20 and R82. You need to add Updateable objects and Domain objects into a Network group named exclusions_RemoteAccessVPN, for example, keeping in mind that
For exclusion mode, the name must begin with:
Ref: Dynamic Split Tunneling for SaaS Using Updatable Objects.
Then the exclusions_RemoteAccessVPN group should be added to the group, which includes the network objects, which will be part of your VPN Domain - the group you specify in the RemoteAccess community (as override) or in the GW object configuration. For example, this group can be called RemoteAccessVPN_Networks. You should not use the exclusions_RemoteAccessVPN group directly as the VPN Domain group (which doesn't make much sense) and for now you can't add the Domain objects to another group, which you will include alongside the Updateable objects in your exclusions_RemoteAccessVPN group. Meaning no recursive resolving is currently possible.
Suggestions: @PhoneBoy
It would be nice if recursive resolving of Domain objects is added as a feature (to allow adding them to a group, which then will be added to the exclusions_ group). This will allow for cleaner configuration and will bi similar to the AD concept of adding Global groups to Domain Local groups.
Additionally, a much better approach would be to add not only company services to the Updateable objects, but similar to what we have there for US government, add other Government sites/domains for each country as Updateable objects. This would mean we have just one "group" added to the exclusions_ group and since Government sites are excluded from HTTPS Inspection and many times blocked from other countries, we will easily exclude them from the RA VPN tunnels.