makes more sense. although i'd still see mac address restrictions being a waste of admin time really. overall network control (and access control) could be achieved via group policy and conditional access. when a device is connected a check is done as to whether it is deemed "safe" or not, based in various criteria. depending on that safe score it either get normal access or client isoliation restricted access.
students should be enouraged to use their own devices rather than being told they can't, just my opinion though.