Yes. You would need a Kerberos realm setup with users principals,and host
principals. Each host has to have a keytab file. One way to use this
is the user gets a ticket on the client, then you use the GSSAPI
options of ssh. There are Windows ssh clients like SecureCRT and some versions
of PuTTY that can do GSSAPI. Windows uses Kerberos so any AD users already
have tickets.

