I've decided to script a temporary transport rule that junks/ quarantines everything ending on "number".onmicrosoft.com using regex expressions.
It seems as if the generated onmicrosoft.com accounts always have a number as last character.
(credits go to Knox203 in this article --> Spam increase from onmicrosoft.com addresses : r/msp (reddit.com) )
However,
Trying to execute this script using the Secure Application Model, it seems as if I have insufficient rights to create transport rules.
I can't find a definitive answer if this is an application permission problem, or that this is by design. I can however if i use interactive signin, without the delegated application permissions.
Any thoughts on this?
We have loads of customers complaining about this rn. Logging into 400 tenants isn't an option unfortunately ;-)