If you want your LDAP resource to deliver profile information, you have two options that affect the possibility to edit fields.
Option 1: Define any field type (like text field or select field) and add an additional LDAP attribute.
If you select any other field type and still select LDAP server as data source, the information will be retrieved from your LDAP resource.
But if the user can't be found in the LDAP resource, the user will be able to edit the field by themselves.
Option 2: Define your field as "Retrieved from LDAP"
This option retrieves the data only from your LDAP resource.
Users will never be able to edit this profile field, even if the user can't be found in the LDAP resource.
Related topic: CUP - Alternative LDAP connection