Hello, I am helping a business set up Microsoft Purview as an intern.
After initial deployment of a couple policies auditing the presence of sensitive data (PII data, credit cards etc), I have proposed only scanning for Credit card information being shared outside of the organisation.
All of the activity was generated from 3 sources, Exchange, OneDrive and SharePoint. The organisation prevents OneDrive and SharePoint links being accessed outside of the organisation so I am focused on Exchange.
Basically my problem atm is when configuring the policy, I can't find an option/exception/condition that will allow me to specify emails sent OUTSIDE of the organisation.