Like many of you, I've rolled my own interpretation of this solution. I've got a self-written MTA that supports any recipient prefixes on emails that are sent to @domain.com. It then firstly checks the RCPT TO: address (the _real_ TO address) against the email aliases assigned to all my users in the Active Directory/Exchange Server. Once that check is passed, it then runs the email through some custom blacklisting rules, and then finally runs the email through SpamAssassin. If the email gets past that, then it gets delivered into the users inbox.
In Active Directory, the proxyAddresses attribute is used to stack up custom <something>@domain.com addresses for each user, which allows for many aliases per inbox. It does require management on the users part - they have to add an alias if want to use it, but that's done via a webform, so easy to do. Likewise they can yank an alias if it's been leaked and gets abused.
This solution has been running for over 5 years now, and it works very very well. The only downside is having to manually add new custom blacklist rules due to the adaptive nature of the spammers.