Absolutely correct for anything downstream of the MX; Meraki switches, access points, cameras etc. In my experience the MX will permit anything that it relies on itself, by way of comms with Dashboard resources.
As pointed out by others; by default all traffic is permitted between VLANs by the MX and from inside VLANs outbound towards the Internet.
Note that if you're using VPN / SD-WAN, the firewall rules that affect in-tunnel outbound traffic are controlled under the Org-wide element of the Security & SD-WAN > Site-to-site VPN configuration. By default all traffic within these tunnels is permitted, for VLANs which are VPN-enabled.