There is nothing actively in-place preventing users specified in Workflow, Forms or Import Agent from logging in through the clients. In United systems, these users can log in. In Avante and Rio, they are only prevented from logging in by the lack of a named user license and Manage Trustees privilege. If you grant them either one, they'll be able to log in. Obviously, granting them a named user license is a waste of a license, but granting them Manage Trustees may be desired in scenarios where Workflow would do trustee administrations tasks.
The inability to log in through the desktop and web client is not a feature and should not be relied on for security purposes. Furthermore, if the credentials leak, the inability to log in through the client apps is not a limiting factor in the potential damage that can be inflicted.