Hello Frank,
refering to the 8.32.x/9.x user guide for my understanding the "Block MU to MU traffic" applied in the advanced configuration option of the wlan service is useable for both B@HWC and B@AP. The blocking mechanismen based on a layer 2 (mac address table of wireless client successfully authenticated on the same SSID, client traffic between clients on the same SSID is blocked).
Policies typically applied at layer 3 level (controller support l2, too). "User Guide, V9.01" page 5-7 include a example for l3 policies/rules to limit client communication applied at B@HWC level. I think its still possible to apply the same rule at ap level. In the user guide on page 5-9 you can explanation of "AP rules/AP filtering" and its limitations.
I agree with John, there a limitations if in multiple controller setups, but this seems not relevant to your user case.
Best regards
Hartmut