@LegoGeek Without involving an SM client install we are wanting to choose where and where not certain clients have access to... in essence, they register their MAC address's and devices and we then "tell them" what they have access to This might, again, not be exactly what you're looking for, but have you seen our new Trusted Access feature? Your use case sounds really similar. https://documentation.meraki.com/zGeneral_Administration/Cross-Platform_Content/Trusted_Access_for_Secure_Wireless_Connectivity Meraki Trusted Access is an easy, secure way to connect iOS, iPadOS, and macOS devices to Meraki MR wireless networks without enrolling the device into Systems Manager. It provides simple, secure certificate-based EAP-TLS authentication, eliminating the need to setup a certificate authority (CA) or RADIUS server. Once you have defined which users can have access to your network, they will be able to download the configuration profile needed to join the SSID from a self-service portal using the authentication method you’ve defined for the network. It's an SM/MR feature but it doesn't require the devices to enroll, and it allows you to have secure client connectivity without RADIUS, you manage them as normal dashboard clients. And you can apply it on an SSID-level, which allows you to separate access to your network resources with standard segmentation. I think it's pretty sleek. Might be helpful?
... View more