StefanoBelluomini - limiting sensitive data in notifications is a setting within an Intune App Protection Policy. First, App Protection Policies are not enabled or assigned to users by default. Second, the setting within the App Protection Policy "Org Data Notifications" is set to Allow by default; this means that all the data is exposed in the notification and not limited in any way. What this means is that an admin within the tenant has to intentionally control how notifications are handled. This means that the control is in hands of the customer, the owner of the data.
There are settings within the mobile device operating system that can also come into play that limits what data is exposed on the lock screen. Outlook has no control over those settings and Outlook respects what the OS notification controls dictate. The APP setting discussed above cannot override the OS control, either.