External accounts such as LDAP users are created having the Contributor role by default. You can change this in the Role Management screen in the control panel. This setting maps to the config setting
security/new-account-role
in the Control Panel/Configuration screen. You can set it to None to have external accounts have no rights or Viewer to allow read only access. Any other valid role name will work as well. Please note that you can also use LDAP groups as a means of giving access to a set of people. More info here