Forbid regular users to alter their user, email data

Hi,

How can I forbid non-admin users from altering account settings? We fetch this information as part of the usage and connect it back to the employees.

just block the endpoints, users won't be able to alter anything