GraphAPI call we originally used/designed RMAD to use with Oauth2 notifications requires Read on the directory (Directory Reader) to validate the Sender was valid.
This was specific to the GraphAPI call that was used. In a future version there will be improvements where only Mail.Send assigned to the App Registration will be required.
Enhancement created: 571169: Email Notifications: Oauth2 remove Directory Reader requirement when using GraphAPI