If you don't have to let all users/machines (including "office1 users") to use the IPsec when the "another interface (MPLS or point-to-point circuit?) " goes down, that's probably the easiest way to do it.
Remember, a policy route "sticks" even when the interface goes down. So if that happens, those "office1 users" can't get to office2 over the IPsec.
If you want to control those situations more flexibly, including based on sources and destinations, you have to set up a SD-WAN zone and put both the IPsec and another interface as members and set proper rules who uses which path in what situations more in detail.
Routing protocols would work for selecting the destinations only. So if you need to control the paths based on the source users/groups, they wouldn't work.
Toshi