You certainly can block calling into voice mail retrieval from auto attendant CRAs etc. by just not equipping any of the digits in digit translation to be SUBSCRIBER ACCESS (usually we put that under "*"). But I'm afraid that once you're in someone's mailbox greeting there's no way to block * from going to subscriber access. If it's not possible to call in to leave messages you're okay, but once you're in a mailbox * is going to work.
Regarding dialing in and back out (traditionally called DISA), that's not natively possible on the 5000 at all, so not a worry. I've set it up for many customers on request, but it requires physically looping SL ports to LS, and I always protect with account codes.