Restricting Managers from Modifying the Employee Type Attribute in the Web Portal, Allowing Only helpDesk Role Members to Edit

How can I restrict that when a Manager creates a new identity from the Web Portal, they cannot modify the value of the Employee Type attribute, and only users who are members of a business role called helpDesk can do so?