Yes, I too was dissapointed that the authorisation controls didn't work in 1.3.7. It would be good to disable a customer account by switching them to 'pending approval' yet leave the account intact so that they cannot re-register using the same email address. This works very well on another CMS I use.

IP banning is a very un-precise solution.

Is this on the to-do list?