This command will disable the user, they won't be able to login, this is the same as unchecking the Unix-enabled check box in Active Directory. The user will still be in the cache however and they can be listed.
/opt/quest/bin/vastool -u <administrator> setattrs <username> loginShell /bin/false