The answer for your question is yes you can achieve that.
The question is how you define those client who should have access and those who should not have access.
If you have list of MACs who should or should not have access then you can define it in radius server and the radius response will inform the AP what access should be granted.
Regards
Zdeněk Pala