a few of ways to do this. If it is one user and you have Active Directory installed, create an Organisational Unit and move the user account and computer account into the OU. Setup a group policy denying access to the network / servers and restricting logon times etc.
If it is just the user account that you want to deny, then dont place the computer account into the OU, just leave the user account in it and that means that no matter what device on the network the user logs onto, they wont have access to the network as the group policy will always be applied
Disable the user account and change the password