Assuming you are talking about WiFi devices, you could use something like WPA2-Enterprise mode, where each device has to authenticate using a username and password. If you use RADIUS then you can push the group policy to use based on the username. If you have a decent RADIUS server, like FreeRADIUS, you could also deny all connections from the MAC address range.
... View more