@discoveranother Here is a few things I would restrict:
-Installing configuration profiles (Meraki can still install them under the management profile, but the pupils cannot install manual payloads.)
-Are you pushing WiFi via a profile and that is going to be the only network they can join? If so, consider using WiFi whitelisting so they cannot tether to their phones to possibly get by your filters.
-Enforce Safari fraud warning
-Restrict erotica in iBooks
-Siri profanity filter
-Diagnostic submission not allowed
-If you are planning on setting the wallpaper, restrict changing that.
-I feel iMessaginf and FaceTime should be turned off if they are school iPads.
Obvously this is is between you and the administration to see what they/you want to restrict.
To answer your second question:
Are you planning on using VPP and DEP and having these devices supervised (I highly suggest all three). If so, you can use the restriction thy disabled the App Store and use VPP for device based app distribution (and an Apple ID on each device would not be nexessary!). What I do is deploy the Meraki MDM app and any other mandatory apps and then place anyone else in the Meraki MDM app to allow the user to install them. *If apps are managed and marked as mandatory (i.e. the Meraki MDM app) and the user deletes it, it will re-install next time the device inventory updates.
Hope that is helpful,
Jared
Find this helpful? Click the kudos button. Thanks!