After a week more of testing, the results are the same as described above. When using MS Graph, emails get stuck in the UNSENT_EMAIL folder but are sent correctly. I can delete them manually, so it’s not the end of the world. Worse is that the settings are not included in the config export, so that I need to apply them manually for each separate Business Space, each time that I publish a new version. That is really inconvenient.
Meanwhile, I found that using SMTP with OAuth also has its problems: emails are sent correctly but are nonetheless filed in the Unsent Email folder and are then automatically sent again after approx. 5 minutes. This means that every email is sent twice, which is confusing for end users.
So neither alternative is ideal at this moment. I would kindly ask to fix the issue with the config export, or else add functionality that the MS Graph settings can also be included in SystemSettings (which would make them independent from the configuration).
The Unsent Email issue can perhaps be fixed by only placing emails there if there is a 400/500 response code from the Microsoft servers, not the 202 code signalling that the email was received for processing.
If there is somehow a callback mechanism used, I’d like to hear when and how so that I can configure the reverse proxy server correctly.