__trj
"It's not completely clear: Will we still be able to relay email through Exchange Online based on the IP address or will a certificate be required (assuming the P1 MAIL FROM requirement 1b is satisfied)?"
Yes, customers still can create Inbound connectors using IP addresses. They only need to use cert based connector when the scenarios apply to them, meaning when they need to relay emails where the envelop sender domain does not belong to their organization.
"We only use the SMTP relay from on-premises applications, scanners, etc. to internal users (email is not destined for recipients outside our tenant). Unfortunately, most of our applications and devices won't be able to support certificates, so we rely on using dedicated IP addresses to route this specific SMTP traffic through at our firewall"
You are OK in this case. Either envelope sender domain or recipient domain belongs to your organization, the relay will just work fine.