O365 oAuth Problem (no application flow?)

As the documentation clearly states, Zammad uses delegated permissions. There’s no workaround or different way to configure permissions so no, application permissions are not supported.

There’s basically a feature request already: Use application permissions for the Microsoft Graph API