yes, but it depends on what version you have.
- For 6.X you still need a domain to import users from, but the machine doesn't have to be member of the domain. You sync up with AD, assign users/groups to that machine, a policy, the software, and it will start encrypting. I had a similar request, and I created a user in AD for the sole purpose of assigning him to the machine that was running outside the domain.
- For 5.X, you have the option to import users from AD, but you can also creat them manually and assign them.