Currently we have a built Azure AD roles which can use to grant the admin consent in API permission in App Registrations (Global Administrator/Privileged Role Administrator).
Both roles have the Highest privileges so need to create the custom role which can do only below function.
Grant the admin consent for tenant in API permission in App Registrations.