Block direct delivery to addresses in a hybrid environment

UPDATE: [11/20/2018] I had an error in the transport rule configuration in the last example, as well as a note that a TR would NDR external traffic.  I have this post accordingly.

We're all familiar with how Office 365 tenants work–when you spin up a new Office 365 tenant, you get a managed domain (