On our lab computers, we've diabled iCloud sign in, as students sign in using their Okta credentials via Jamf Connect and we typically don't want them junking up the computers with their personal iCloud stuff. We have a fair number of students with their own personal iPads and Apple Pencils, and they'd like to use those devices with the lab computers, but Apple requires both devices to be signed into iCloud with the same ID. I know I can re-enable iCloud sign in, but that seems like it opens up the computer to being "owned" by anyone who signs in and also allows iCloud syncing, which we don't want.
So, my question is are there any established models for loosing up the restrictions enough to allow Sidecar?