Few things I don't like:
SecureConnect will automatically place these MR access-points in the same VLAN as the management VLAN of the switch they are connected to.
Not a fan of this and they should allow in the future the ability to specify management VLAN for wireless. I don't always use the same VLAN for switch and AP subnets.
Assuming authenticated, the "Allowed VLANs : All VLANs"
I specifically go out of my way to only allow VLANs with SSID's tied to them (and management for AP) on these ports. Hopefully they allow this to be configured in the future.