Registering Email Engine with Microsoft Azure for OAuth 2.0 authentication
To register the application for OAuth2 Authentication
See the "Register your application" and "Configure for app-only authentication" sections in the Authenticate an EWS application by using OAuth page.
To restrict mailbox access
See New-ApplicationAccessPolicy.
Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*