Hi,
What you can do, although not a very pretty construction:
1. Create an account for the external user in your AD
2. Create a Meraki group policy with firewall rules as required for this user
3. Once the user has connected the first time, apply the policy to the client from the client page
This works best when the default network firewall does not allow any traffic from client VPN subnet, and then this way you will be able to authorize them after first time connect.