I know that it's possible to create different groups of devices in LMS through ACS, in such a way that a specific user cannot access to devices not assigned to him.
Is it possible to do it with a FreeRadius instead of a ACS?
However, this will not work with LMS. In order to restrict what devices an LMS user can manage, you need Cisco Secure ACS.
No. ACS and TACACS+ are required to do this. With only a Radius server, you will only be able to provide external centralized authentication. None of the custom roles or device grouping capabilities will be available.