jcgonzalezmartin, I'm having a little trouble parsing your question but I assume you're asking why we are using security groups instead of O365? We tend to use SG's for policy related features as they don't have any associations for other apps (for example, showing up in Outlook or seeing other people in the group). Do you have a case in mind where you would rather use an O365 group?
Nathan Wells, to answer your questions:
1) Correct. If the checkbox for this feature is checked and the user is not in one of the security groups, they cannot share externally.
2) This is scoped to the tenant only.
Avian 1, what this feature will let you do is only allow people in the "corporate users" security group share externally. They will still be able to share externally to any user.
Hope that helps!
Stephen Rice
OneDrive Program Manager II