If you have the list of exceptions in - Skipping HTTPS decryption, Malware & Policy checks - and they're showing up in the Log Viewer->Web Filter log as having those applied (EG "domain="outlook.office365.com", exception="av,https,policy,zero-day protection,validation"), then you should be good on that side of things.
If you create an 'allow all' firewall rule on the XG for your test machine (LAN->SourceIPAddress, WAN->Any, no web policy attached = no filtering), that should give you an idea on whether there's a problem on the firewall or not.
And, I'm sure you've already tried it, but there's an Outlook Connectivity Assistant tool here from Microsoft which may help identify any client-side / connetivity issues: http://tinyurl.com/mrxzwd6f