Not without encryption of boot volume, and only on TPM-less machines, and only on Windows 8 and later.
Using an unencrypted boot volume by the way is asking for everyone with physical access to the machine to become local admin, and/or add key loggers…