> Isn't that how things are supposed to work?
If your company is prioritizing security and privacy, no, this is not how it's supposed to work.
This shows a failure of the process. By design/default, this MAC address should not be available to system or user processes in IOS. In general, even the randomized MAC address should not be available. The fact that it was available to the mDNS process indicates that there was no security/privacy review of its existing access, no technical measure implemented to break that access until a review or exception was put into place, and no test plan that validated that the MAC address is never sent on the WIFI radio.