We use Cisco Umbrella for our DNS queries, but the interception happens on the Meraki MX side. Upon further investigation it looks like the Meraki "strict" YouTube setting is working on all levels. From our tests if a user is not signed into their Google accounts then the MX Strict setting is applied. If they're logged into their org account then it defers to the Google Admin settings. We're finding the MX strict and Google strict are slightly different.
We're having issues with students and non-edu related content (not necessarily improper). At first we though they could bypass by logging into a commercial Google account. It appears that's not the case as so far it looks like the MX default strict applies. We're still testing some more.