Like a number of other organizations, we are considering putting in place some kind of notification branding externally sourced messages, i.e. "This message was received from outside our company. Please exercise caution."
Policy tips would be preferable to stamping a text disclaimer on the message, as this would keep the text out of the message body and out of e-mail threads to and from our clients. However, it seems as if policy tips in Exchange Online or Exchange 2016 On-Prem
are constrained for use with DLP only:
https://docs.microsoft.com/en-us/exchange/security-and-compliance/data-loss-prevention/manage-policy-tips
"In Apply
this rule if, select, The
message contains sensitive information. This condition is required."
Has anyone come up with a workaround for this DLP or "sensitive information" requirement? We want it to apply to all externally sourced messages regardless of the content. I saw there are ways to create a custom sensitive information type,
but it's not clear to me whether you can create a sensitive information type that applies to all messages.