I've seen the Meraki doc page, and it doesn't say how to issue the client cert.
And thanks for the Microsoft page, however the 3rd step (Request a New Cert) is not the same as what I see on my 2012R2 server... in particular the dialog for "Select Certificate Enrollment Policy" only has "Active Directory Enrollment Policy" (then select Administrator, Basic EFS, EFS Recovery Agent, or User) and "Configured by you" (which requires me to enter "enrollment policy server URI").
Thanks