Great advice from Christian.
In addition, bear in mind that FSE is designed to do the majority of internal and outbound mail scanning at the Hub level. If you only install FSE on mailbox servers, you will be putting a high load on those servers, as regards scanning.
Where FSE is installed on Hub and Mailbox servers, load is taken off the mailbox servers, as most scanning will be done at the Hub level (even for local deliveries). This is therefore my own bare-minimum recommendation. Then add FSE on the Edge servers too, if you have them...but this is the optional part, IMHO.
Kind Regards,
Andy Day | CSS Security, Sr. Support Engineer (Antigen/Forefront Server Security)