See explanation below.
Explanation
Go to Mail flow > Rules.
Create the rule by using one of the following options:
- To create a rule from a template, click
- To copy a rule, select the rule, and then select
- To create a new rule from scratch,
In the New rule dialog box, name the rule, and then select the conditions and actions for this rule:
- In Apply this rule if..., select the condition you want from the list of available conditions:
Some conditions require you to specify values. For example, if you select The sender is... condition, you must specify a sender address. If you're adding a word or phrase, note that trailing spaces are not allowed.
If the condition you want isn't listed, or if you need to add exceptions, select More options. Additional conditions and exceptions will be listed.
If you don't want to specify a condition, and want this rule to apply to every message in your organization, select [Apply to all messages] condition.
- In Do the following..., select the action you want the rule to take on messages matching the criteria from the list of available actions:
Some of the actions will require you to specify values. For example, if you select the Forward the message for approval to... condition, you will need to select a recipient in your organization.
If the condition you want isn't listed, select More options. Additional conditions will be listed.
- Specify how rule match data for this rule is displayed in the Data Loss Prevention (DLP) reports and the Mail protection reports.
- Set the mode for the rule. You can use one of the two test modes to test the rule without impacting mail flow.
In both test modes, when the conditions are met, an entry is added to the message trace:
Enforce: This turns on the rule and it starts processing messages immediately. All actions on the rule will be performed.
Test with Policy Tips: This turns on the rule, and any Policy Tip actions ( Notify the sender with a Policy Tip) will be sent, but no actions related to message delivery will be performed. Data Loss Prevention (DLP) is required in order to use this mode.
Test without Policy Tips: Only the Generate incident report action will be enforced. No actions related to message delivery are performed.
Exchange Online admins can create mail flow rules in the Exchange admin center (EAC) at Mail flow > Rules
. You need permissions to do this procedure. After you start to create a new rule, you can see the full list of attachment-related conditions by clicking under Apply this rule if. The attachment-related options are shown in the following diagram.
Graphical user interface, application Description automatically generated with medium confidence

Reference:
https://docs.microsoft.com/en-us/exchange/security-and-compliance/mail-flow-rules/manage-mail-flow-rules
https://docs.microsoft.com/en-us/exchange/security-and-compliance/mail-flow-rules/inspect-message-attachmen