IT's a good practice to not have mesh enabled on APs that are connected via the wire. I would suggest you set any AP that is not intended to be a mesh AP to ROOT only mode or if you are running newer versions of code you can disable mesh on a per AP ...
Yes and NO,
Yes you can change the vlan but there is no way to tell the client you have done so.
So the client will get an IP address authenticate then if you change the vlan it will have the wrong IP.
Now if you introduce a NAC solution such as ...