Not directly possible from SEPM policy. A workaround you can use is to:
1. block access to USB devices per Application and Device Control Policy
2. lock the access to SEP client GUI with password
3. allow option for disabling the Application and Device Control feature from client GUI
...this way to allow the blocked usb temporarily - you can access SEP GUI with password and disable the Application and Device Control from there - this will unlock USB devices for you to use