ORCA (Office 365 ATP Recommended Configuration Analyzer)
Community-developed checks for Defender for Office 365 configuration, originally created by Cam Murray.
Official documentation68
Controls
62
Auto-Remediable
1
Domains
Exchange(68)
ORCA-100Bulk Complaint Level threshold is between 4 and 6.
ORCA-1000Exchange Online Protection (EOP) is enabled.
ORCA-1001Spam filter policy settings configured.
ORCA-1002Malware filter policy settings configured.
ORCA-1003Phishing filter policy settings configured.
ORCA-1004<URL> filtering policy settings configured.
ORCA-101Bulk is marked as spam.
ORCA-102Advanced Spam filter options are turned off.
ORCA-103Outbound spam filter policy settings configured.
ORCA-104High Confidence Phish action set to Quarantine message.
ORCA-105Safe Links Synchronous URL detonation is enabled.
ORCA-106Quarantine retention period is 30 days.
ORCA-107End-user spam notification is enabled.
ORCA-108DKIM signing is set up for all your custom domains.
ORCA-108.1DNS Records have been set up to support DKIM.
ORCA-109Senders are not being allow listed in an unsafe manner.
ORCA-110Internal Sender notifications are disabled.
ORCA-111Anti-phishing policy exists and EnableUnauthenticatedSender is true.
ORCA-112Anti-spoofing protection action is configured to Move message to the recipients' Junk Email folders in Anti-phishing policy.
ORCA-113AllowClickThrough is disabled in Safe Links policies.
ORCA-114No IP Allow Lists have been configured.
ORCA-115Mailbox intelligence based impersonation protection is enabled in anti-phishing policies.
ORCA-116Mailbox intelligence based impersonation protection action set to move message to junk mail folder.
ORCA-118.1Domains are not being allow listed in an unsafe manner in Anti-Spam Policies.
ORCA-118.2Domains are not being allow listed in an unsafe manner in Transport Rules.
ORCA-118.3Your own domains are not being allow listed in an unsafe manner in Anti-Spam Policies.
ORCA-118.4Your own domains are not being allow listed in an unsafe manner in Transport Rules.
ORCA-120.1Zero Hour Autopurge Enabled for Phish.
ORCA-120.2Zero Hour Autopurge Enabled for Malware.
ORCA-120.3Zero Hour Autopurge Enabled for Spam.
ORCA-121Supported filter policy action used.
ORCA-124Safe attachments unknown malware response set to block messages.
ORCA-139Spam action set to move message to junk mail folder or quarantine.
ORCA-140High Confidence Spam action set to Quarantine message.
ORCA-141Bulk action set to Move message to Junk Email Folder.
ORCA-142Phish action set to Quarantine message.
ORCA-156Safe Links Policies are tracking when user clicks on safe links.
ORCA-158Safe Attachments is enabled for SharePoint and Teams.
ORCA-179Safe Links is enabled intra-organization.
ORCA-180Anti-phishing policy exists and EnableSpoofIntelligence is true.
ORCA-189Safe Attachments is not bypassed.
ORCA-189.2Safe Links is not bypassed.
ORCA-205Common attachment type filter is enabled.
ORCA-220Advanced Phish filter Threshold level is adequate.
ORCA-221Mailbox intelligence is enabled in anti-phishing policies.
ORCA-222Domain Impersonation action is set to move to Quarantine.
ORCA-223User impersonation action is set to move to Quarantine.
ORCA-225Safe Documents is enabled for Office clients.
ORCA-226Each domain has a Safe Link policy applied to it.
ORCA-227Each domain has a Safe Attachments policy applied to it.
ORCA-228No trusted senders in Anti-phishing policy.
ORCA-229No trusted domains in Anti-phishing policy.
ORCA-230Each domain has a Anti-phishing policy applied to it, or the default policy is being used.
ORCA-231Each domain has a anti-spam policy applied to it, or the default policy is being used.
ORCA-232Each domain has a malware filter policy applied to it, or the default policy is being used.
ORCA-233Domains are pointed directly at EOP or enhanced filtering is used.
ORCA-233.1Domains are pointed directly at EOP or enhanced filtering is configured on all default connectors.
ORCA-234Click through is disabled for Safe Documents.
ORCA-235SPF records is set up for all your custom domains.
ORCA-236Safe Links is enabled for emails.
ORCA-237Safe Links is enabled for teams messages.
ORCA-238Safe Links is enabled for office documents.
ORCA-239No exclusions for the built-in protection policies.
ORCA-240Outlook is configured to display external tags for external emails.
ORCA-241Anti-phishing policy exists and EnableFirstContactSafetyTips is true.
ORCA-242Important protection alerts responsible for AIR activities are enabled.
ORCA-243Authenticated Receive Chain is set up for domains not pointing to EOP/MDO, or all domains point to EOP/MDO.
ORCA-244Policies are configured to honor sending domains DMARC.
