Hello,
Yes, If a user creates an e-mail from your Internal Environment (secured with SEP) with an Html malware as the message, SEP would stop this from going out prior to our Exchange server security.
Only condition is that the SEP with Outlook protection feature has to be Installed and Enabled.
NOTE: Symantec Excludes the Exchange Folders from Scanning.
Symantec Endpoint Protection would block against any malicious activity which gets performed on your Environment which is Protected.