Avoid the forwarding to external addresses in Microsoft Flow
Microsoft Flow allows the creation of a simple flow by using Outlook connector, which forwards a message to an external address.
It happens despite you don't allow that in Exchange Online --because you have the auto-forward disabled in the default remote connector--.
Therefore, it creates a security and data loss protection issue because we don't allow the users the creation of mail rules to auto-forward messages to outside, but they can create a simple flow to do the same.
Is there a way Microsoft Flow can control that? We have opened a ticket with MS, but since Flow does not use any attribute in the message header, there is no way to create a transport rule to block that.
It would be great if there was a setting to not allow the flow to external adddress, so the user can only redirect messages to internal (accepted) domains.