Thank you for asking this question on the **Microsoft Q&A Platform. **
If you what that Help Desk just can do a specific activity, you need to create a Custom Role https://learn.microsoft.com/en-us/azure/active-directory/roles/custom-create
If You what that Help Desk can read everything in your Azure AD, you can assign them a Global Reader Role.
Hope this helps,
Carlos Solís Salazar
Accept Answer and Upvote, if any of the above helped, this thread can help others in the community looking for remediation for similar issues.
NOTE: To answer you as quickly as possible, please mention me in your reply.