Peter_Holdridge thank you for your comment, especially that security is our top priority. With the HVE we are separating HVE traffic from your Tenant mailboxes. With HVE we are providing dedicated end point which do not interact with mailboxes. Based on the documentation:
If Security Defaults is enabled, all basic authentication including SMTP is disabled, making High Volume Email (HVE) non-functional.
HVE accounts can operate even if SMTPClientAuthenticationDisabled is set to True within TransportConfig, due to the use of the custom endpoint.
To avoid any impact from authentication policies, it's important for customers to ensure AllowBasicAuthSmtp is enabled in their organization for the HVE account. Custom authentication policies can be applied to the HVE accounts as needed.
If there is a need to be fully (physically) separate from your tenant, you can use Azure Communication Services Email with also dedicated SMTP end point.