It really depends on the level of protection you're aiming for. If your priority is purely detecting PII within emails, then M365 DLP policies can do a solid job. But if your strategy also needs to cover human error - misaddressed emails, incorrect attachments, Cc/Bcc mistakes, and contextual encryption - then something more advanced, like Egress, is worth a look.
Now they've been acquired by KnowBe4, the human risk management side has developed a lot - we've had great customer feedback on the integration (automated simulations/training assigned based on the types of phishing threats a user actually receives etc.).