Many APs feature “hidden SSID”, yet a rogue can associate.
With MikroTik Router OS, you can control the security policy and therefore which mac addresses are permitted to associate.
Wireless/Association list (in Winbox) can be used to build the list of authorized mac addresses. One can also use the Wireless/Security tab to achieve your results.
ACHTUNG! If doing this for a production link, you must have good records (read: lab notes) regarding the configuration so you can minimize the downtime associated with changing equipment on a non-redundant link.
While it may not be necessary this week, you might eventually want to control your MikroTiks with well known and reproducible configurations. Starting at /system reset and going from there with a saved text file is an alternative.
We keep our Cisco configs in a CVS vault using rancid and are working on extending this level of documentation to cover the MikroTiks.