This may help. 3185209
Allow Help Desk to view only Bitlocker Key in Intune/Azure?

We have a 3rd party support agency that handles about 200 of our laptops. They are all Azure AD joined. We want to give them rights to retrieve only bitlocker key information. What is the most restrictive way to setup the new support accounts to do this? They don’t currently have accounts to sign into our tenant. We don’t want to them to be able to assign policies or software or modify any Azure/Intune settings. Later on down the road, we may want to allow them to view device information (in addition to bitlocker keys) for them to see what applications might be installed or collect diagnostic data and so on. But first we are starting with just bitlocker information.