I have seen this happen before. I don't like restricting unnecessarily, but some students might benefit from a stricter rules set.
I think I would try a set of settings here. Distribute a wifi profile with auto-join if available enabled. Then, in a restrictions profile, force wifi to be on, disallow modification of VPN settings, and turn off iCloud private relay. Consider turning off nearby password sharing and Airdrop password sharing. Yes, they are 2 different settings.
If they do not take their iPads home, consider to turn on the option to only join wifi networks configured with a profile. The last one here might be handy for those who have abused the system and needs to work on-device only. DNS settings can be configured in a profile, and turn off the option for users to modify. This is the option your network team might like the least, as it requires more maintenance.
Bundle with Jamf Safe Internet might also be an option, since that creates a VPN and is on-device.
Limit IP Address Tracking is not available in the Wi-fi payload, allow iCloud Private relay is unticked in my organisation, however I can tell you that it is still putting itself on in the Wi-fi settings.