The trivial defense against this is time limited passwords for Wifi access. Deny all access until a valid password is entered, only permit that password and MAC address pair for n minutes.
Buy a coffee, get a new password, etc.
Buy a coffee, get a new password, etc.
Their employees' time is more effectively spent making coffee than repeatedly providing low-level tech support for random password problems.