If he tested with a allow list, it doesn't make sense.
Allow List
Applies the following settings to a client:
Is exempt from all firewall rules, both Layer 3 and Layer 7 (Applies to both the MX Security Appliance and the MR Access Points)
Bypasses AMP
Bypasses a Click-through Splash page
Bypasses a Billing (paid access) Splash page and access the network on an SSID without paying or authenticating
Bypasses a Sign-on Splash page without authenticating (Applies to both the MX Security Appliance and the MR Access Points)
Is exempt from Per-client bandwidth limit (Applies to both the MX Security Appliance and the MR Access Points)
Is exempt from Traffic shaping rules (Applies to both the MX Security Appliance and the MR Access Points)
Bypasses Content filtering on MX Security Appliance
I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.
Please, if this post was useful, leave your kudos and mark it as solved.