Number of different ways. For regular staff we provide equipment for them, and have it set up that is can only connect to our VPN prior to log on to ensure that the device can only be used on our network.
Off-Shore RDP into VM Workstations in our DMZ, where firewall rules restrict where, and what , can get into our network, though this is being changed to a Citrix solution in the near future.