Hi Muhammad,
In order to allow inbound/outbound emails through the ESA, you would need to confirm if you have dedicated IP's from the O365 servers or if they are dynamic/shared.
All connections coming to the ESA would match the HAT sender groups first based on the sending server IP/hostname, sender group with relay action is considered outbound while all others are considered inbound.
All connections leaving the ESA would use SMTP routes or DNS to deliver emails to the next hop.
So based on your requirement of email flow you would need to add IP's to the HAT sendergroup and SMTP routes for emails inbound and outbound.
I wasn't able to locate any specific article for the same, since the configuration would vary depending on the specific requirement of the organization.
Thank You!
Libin Varghese