Hello,
when I need client isolation in flexconnect mode, in a simple network, without redundant links between Catalyst,
I configure in the Catalyst the "switchport protected" command in the AP ports and in the downlink trunks.
It is a simple way when you do not need connectivity between other vlans different from those used in wireless.
Be carefoul, this way there's not connectivity between AP, some features will not work as "Flexconnect AP Upgrades"