The following configuration will...
a) allow webmail access to the global directory either from the internal or public internet (restricted to valid users--who have to first provide a valid userid/password to logon to access webmail)
b) allow Thunderbird and Outlook access to the global directory for local users (who are on the internal network--with or without a validated logon)
c) disallow external access from the public internet
...the configuration is: from the server-manager->Configuration->Directory panel, set LDAP directory access to 'Allow access only from local network'
Additionally, if you want to allow Thunderbird and Outlook access from the internet--but only to valid users, then one solution is for users to access the internal network using a VPN connection (and don't change the above configuration)