If it is for one particular user, you probably could setup a rule above the blacklist one and base it off the IP of their machine, but otherwise, no. I think you would need deep packet inspection in order to provide that level of granularity. I don't think Ironport WSA can do this. It can't do Citrix traffic, so I doubt it could do this.