Thank you for asking this question on the **Microsoft Q&A Platform. **
If you what that Help Desk just can do a specific activity, you need to create a Custom Role https://learn.microsoft.com/en-us/azure/active-directory/roles/custom-create
If You what that Help Desk can read everything in your Azure AD, you can assign them a Global Reader Role.
Hope this helps,
Carlos Solís Salazar
----------
Accept Answer and Upvote, if any of the above helped, this thread can help others in the community looking for remediation for similar issues.
NOTE: To answer you as quickly as possible, please mention me in your reply.