Hi @Muhammad Rahman ,
I have found the solution
Great to know that you've already thought of a solution and really appreciate it for your sharing!
By the way, since the Microsoft Q&A community has a policy that "The question author cannot accept their own answer. They can only accept answers by others.". and according to the scenario introduced here: Answering your own questions on Microsoft Q&A, I would make a brief summary of this thread:
【RBAC - Which Role type would give admins to create email alias in "Microsoft 365" group?】
Issue Symptom:
Which Role type would give admins to create email alias in "Microsoft 365" group?
I have tried exchange admin and group admin but still no luck for Microsoft 365 groups?
The Solution:
when assigning roles to admins they will need to be directly added to the PIM role for Exchange Admin. I currently had the admins in a security group (already been enabled for Azure AD Roles) but for the Exchange Admin role if they are in that security group it gives them all access to Exchange Admin except the ability to create email alias only for "Microsoft 365" group but for anything else in Exchange they get full access.
You could click the "Accept Answer" button for this summary to close this thread, and this can make it easier for other community member's to see the useful information when reading this thread. Thanks!