Deleted - Part of the issue is MS has a number of anonymous calls built into EWS and Autodiscover to find the correct endpoint URL for a specific mailbox. When running mailbox migrations pre-auth will cause failed move events.
I have a number I have large enterprise customers who have been frustrated with this same issue (not supporting pre-auth) and we were able to get approval to publish by limiting inbound connections to Exchange & Teams IP blocks.
With F5 ASM modules you also need to make sure you enable learning mode while starting to prep mailbox migrations as a number of move processes can be incorrectly blocked and labeled as SQL injections or 400/500 error responses.