Hello Mike,
The scope as well as refresh tokens are NULL for client cred flow - As there is no need to have any user intervention to renew the token, this set-up should just work.
Please follow the detailed instructions for setting up the Azure App (for Client Credentials flow) and required permissions (e.g. IMAP.AccessAsApp) and Admin consent for this permission. You would also need to register the Azure application’s service principal in Exchange with help of Administrator. Detailed instructions can be found in this section.
Hope this helps!.