Probably, but you'd probably be talking about created a filter driver to prevent access to the devices pre-authentication.  Driver development isn't trivial even for most business app developers.
Of course if they're already logged in then they would technically be authenticated, so a group policy could accomplish the same thing to a degree.