This question was raised in the 'How to implement a secure IoT system on ARMv8-M' webinar, view all the questions in the round up blog post.
Yes, it is possible for secure code to do this by reprogramming the SAU. It's also possible to reconfigure a region to from secure to non-secure, provided that the IDAU doesn't already mark that region as secure.