This is the default setting for anyconnect.
To override this you'll need to create/modify the xml profile used in their group-policy.
The default setting in the profile is :
true
When you modify the profile you can set it to false:
false
This controls AnyConnect client behavior when started. By default, the
client will attempt to contact the last Gateway a user connected
to or the first one in the list from the AnyConnect profile. In
the case of certificate-only authentication, this will result in
the establishment of a VPN tunnel when the client is started.
more here:
http://www.cisco.com/en/US/partner/docs/security/vpn_client/anyconnect/anyconnect25/administration/guide/ac03features.html#wp1215263
hth,
rob