Thanks for reaching out to Microsoft Q&A
All the permissions that need to be consented by an Admin will need to be consented either by the GA or by using an Admin consent workflow.
The admin consent workflow gives admins a secure way to grant access to applications that require admin approval. When a user tries to access an application but is unable to provide consent, they can send a request for admin approval. The request is sent via email to admins who have been designated as reviewers. A reviewer takes action on the request, and the user is notified of the action.
The documentation below has more information about how to create such consent flow:
https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/configure-admin-consent-workflow
Let me know if you have further questions or if I misunderstood your request.
Thanks,
Fabio