Hello @Baylar_Ismayil ,
Nice to see you again~
To answer your first question, Exchange Server can differentiate between internal and external log-in connection requests based on the source IP address of the incoming request. If the source IP address is within the range of IP addresses that are defined as internal, the connection is considered internal. Otherwise, it is considered external.
Regarding your second question, since the command is not work, I recommend to look into different options to limit external access on user and protocol level (such as ADFS or CA or IPsec) to block external log-in connections to Exchange Server 2019. Thanks for your understanding.
Reference:
Please Note: Since the web site is not hosted by Microsoft, the link may change without notice. Microsoft does not guarantee the accuracy of this information.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.