I have used a separate SSID in it's own VLAN that has a dedicated MX for it. The VLAN has no interfaces on the main corporate network switches or MXs. To be super secure you could make the SSID tunnel back to the separate MX.
If my answer solves your problem please click Accept as Solution so others can benefit from it.