Are you asking about outside clients getting in? If so, that should be done via remote access VPN.
If you're asking about internal users getting out, then they should all be subject to the firewall's ACLs and inspections etc.
In either case, it's very unwise to blanket exempt a given user or group from the organization security policy as implemented in part on the firewall.