If an email is sent to external recipients, or is received from external senders, is this considered a document exposure for the purposes of DLP policies?
Office 365 Email DAR
Yes.
If an email is sent to an external recipient and later scanned with the Office 365 email securlet, a policy looking for 'Document is Exposed' will trigger as this value will be 'true'
This also means that externally sent emails will always trigger the condition of Document is Exposed when picked up by the Office 365 for email securlet, this can lead to many false positives.
To prevent false positives from received emails in this manner, create an exception matching both:
1. Document is exposed = true
2. Application Name is Any of: Office 365 Email Securlets