How to Configure MS Exchange Outlook (Microsoft 365) – Outgoing Only

1.1 Where to Configure

Policy Management → Edit Policy → Data Loss Prevention → MS Exchange Outlook (Microsoft 365) panel

1.2 Exchange Protection Settings

Setting
What it does
MS Exchange Outlook (Microsoft 365) checkboxMaster switch for entire setting.
Exchange Mode MonitoringON/OFF toggle for active monitoring of the Exchange mail flow.
Action: Report Only / Block & ReportReport Only logs violations but lets mail through. Block & Report stops the mail and logs it.
Enable AlertShows a popup notification to the client when a mail is blocked.
Outgoing Mail ExtensionAllow/block-except-exception logic applied to Exchange outgoing attachments (extension or file name).
Max Allowed Attachment Size (MB)Outgoing mail with attachments larger than this limit is blocked.
Block CcBlocks the mail outright if a Cc recipient is present.
Block BccBlocks the mail outright if a Bcc recipient is present.
1.3 Step-by-Step: Configuring Exchange Protection
  1. Go to Policy Management → Edit Policy → Data Loss Prevention → MS Exchange Outlook (Microsoft 365).
  2. Tick the main checkbox on the panel.
  3. Set Exchange Mode Monitoring to ON.
  4. Choose Report Only or Block & Report, and tick Enable Alert if end users should be notified.
  5. If restricting attachments, tick Outgoing Mail Extension, pick a mode, and add extensions/file names to the list.
  6. Set Max Allowed Attachment Size (MB), and tick Block Cc / Block Bcc if required.

Save/Update the policy and push it to the target client group.

1.4 Outgoing Domain Restrictions

This is the Exchange module’s equivalent of Spam Protection — it restricts outgoing mail to a whitelist.

1.5 Step-by-Step: Configuring Outgoing Domain Restrictions
  1. tick “Outgoing Domain Restrictions.”
  2. Choose the mode from the dropdown (e.g. Block All Except Exception).
  3. Add allowed domains under “Enter Domain for Allow…” and/or allowed addresses under “Enter Email id for Allow…” — both lists can be used together.
  4. Save/Update the policy.
1.6 Sensitive Data Scanning (Outgoing Mail)

This panel sits under the same Data Loss Prevention page but is shared across several DLP channels, not just Exchange mail. For email-protection purposes, only the fields below are in scope:

SettingWhat it does
Scan Outgoing MailsMaster switch that applies sensitive-data scanning to outgoing mail.
Personal Details categoriesEmail Address, Driving License Number, Mobile Number, Passport Number, Pancard Number, Aadhar Card Number — tick any that should trigger a block/flag if found in outgoing mail.
Credit/Debit Card categoriesMaster Card, Visa, Amex, Discover, JCB, American Express — tick any card types to detect.
Add Keyword to MonitorFree-text keywords that also trigger detection when found in outgoing mail.
1.7 Step-by-Step: Configuring Sensitive Data Scanning for Outgoing Mail
  1. Tick the main “Sensitive Data Scanning” checkbox to expand the panel.
  2. Tick “Scan outgoing mails.”
  3. Under Personal Details and/or Credit/Debit Card, tick the categories that should be detected.
  4. Optionally add free-text keywords under “Add Keyword to Monitor.”
  5. Ignore the remaining fields on this panel — they belong to other DLP channels.
  6. Save/Update the policy.