You can use Data Conditions to identify and track sensitive content for documents and emails maintained with Azure Information Protection encrypted documents in the classifications.
Make sure that your Azure server is defined as a Registered Servers in ePO - On-prem. For more information about registering Azure servers, see Configure the registered Azure server in ePO - On-prem for Microsoft Information Protection with Trellix DLP Network.
Create and configure sensitivity labels and their policies in Microsoft Purview. For more information, see https://learn.microsoft.com/en-us/microsoft-365/compliance/create-sensitivity-labels?view=o365-worldwide#create-and-configure-sensitivity-labels.
In ePO - On-prem, select Menu → Data Protection → Classification.
Click New Classification.
Type a unique name and an optional description.
Click Actions, then select New Content Classification Criteria.
Select Data Conditions. You can include keyword, advanced patterns, dictionary, proximity or exact data matching criteria.
Click + to add another name / value pair.
Click Save.
Create an Email protection rule or Web protection rule using this classification.
For information about how to create a rule, see Create a rule with classification grouping.
Assign the rule to a rule set and then assign the rule set to policies.
For more information, see Create a rule set.