The Built-in AzureAD connector can't manage Exchange groups (mail-enabled security groups and distribution lists).
This is due to a limitation of the Microsoft Graph API and understandable.
However, when configuring Business Rules, the Exchange groups are still shown.
Please filter this down to only manageable groups to avoid confusion (and possibly a lot of errors).