Well what exactly is limited access? If its just Internet only you can do this many ways. First you can use ACLs on the WLC to block traffic to your local network and just allow Internet, dhcp and dns. Or you can do this on the layer 3 interface which I prefer. The other way is to just use one port for your internal traffic and another port connected to your dmz.
So there are many ways, but most if them doesn't involve doin anything on the WLC unless you use ACLs on the WLC.