I need users to log in to be able to enrole in password self service. This option would not solve my issue. My issue is a user can log in and change attributes on thier account in AD, Attributes we are going to use in the future which can not be modified by end users like Phone numbers, notes, and other stuff.
I tried to remove from the self service view in the management area:
I also set access on using a Adaxes security group.
And set the access in the web configurator.
Yet my test user can update the fields