Or the other, perhaps more simple way is to create L3 Firewall Rules that block access from your Guest SSID VLAN to RFC1918 destinations.
I personally like the Group Policy method a bit better as it separates that VLAN's rules into a different window, but both methods work fine.
Whilst I am a Meraki employee, some of what I post may be opinion (especially architecture!). Others may have better or more efficient ways of doing things, so please learn from everyone!