Instant does not have the concept of Virtual APs the way the controller-based architecture does. Please see the attached CLI user guide, specifically the section on wlan ssid-profile.
As you mention, you can use AirWave (or Aruba Central) to configure the Instant APs as well. AirWave offers both template based configuration and GUI configuration.
wlan ssid-profile <ssid_profile>
a-max-tx-rate <rate>
a-min-tx-rate <rate>
air-time-limit <limit>
auth-server <name>
auth-survivability
bandwidth-limit <limit>
blacklist
broadcast-filter <type>
captive-portal {<type>[exclude-uplink <types>]|external[exclude-uplink <types>| profile
<name>[exclude-uplink <types>]]}
content-filtering
deny-inter-user-bridging
deny-local-routing
disable
dmo-channel-utilization-threshold <threshold>
dot11k
dot11r
dot11v
dtim-period <value>
dynamic-multicast-optimization
enable
enforce-dhcp
essid <essid>
external-server
g-min-tx-rate <rate>
g-max-tx-rate <rate>
hide-ssid
hotspot-profile <name>
inactivity-timeout <interval>
index <idx>
key-duration <duration>
l2-auth-failthrough
leap-use-session-key
local-probe-req-thresh <threshold>
mac-authentication
mac-authentication-delimiter <delim>
mac-authentication-upper-case
max-authentication-failures <limit>
max-clients-threshold <Max_clients>
multicast-rate-optimization
okc-disable
opmode <opmode>
per-user-bandwidth-limit <limit>
radius-accounting
radius-accounting-mode {user-association|user-authentication}
radius-interim-accounting-interval <minutes>
radius-reauth-interval <minutes>
rf-band <band>
server-load-balancing
set-role <attribute> {{contains|ends-with|equals|matches-regular-expression|not-equals|starts-with} <operand> <role>|value-of}
set-role-by-ssid
set-role-mac-auth <mac_only>
set-role-machine-auth {<machine-only>|<user-only>}
set-role-pre-auth <role>
set-role-unrestricted
set-vlan <attribute> {{contains|ends-with|equals|matches-regular-expression|not-equals|starts-with} <operand> <vlan>|value-of}
termination
type {employee|voice|guest}
vlan <vlan>
wep-key <wep-key>
wispr
wmm-background-dscp <dscp>
wmm-background-share <share>
wmm-best-effort-dscp <dscp>
wmm-best-effort-share <share>
wmm-video-dscp <dscp>
wmm-video-share <share>
wmm-voice-dscp <dscp>
wmm-voice-share <share>
work-without-uplink
wpa-passphrase <wpa-passphrase>
zone <zone>
no…