← All Frameworks

ORCA (Office 365 ATP Recommended Configuration Analyzer)

Community-Based

Community-developed checks for Defender for Office 365 configuration, originally created by Cam Murray.

Official documentation

68

Controls

62

Auto-Remediable

1

Domains

Exchange(68)

ORCA-100

Bulk Complaint Level threshold is between 4 and 6.

medium
Auto-remediable
ORCA 100
ORCA-1000

Exchange Online Protection (EOP) is enabled.

high
ORCA 1000
ORCA-1001

Spam filter policy settings configured.

high
Auto-remediable
ORCA 1001
ORCA-1002

Malware filter policy settings configured.

high
Auto-remediable
ORCA 1002
ORCA-1003

Phishing filter policy settings configured.

high
Auto-remediable
ORCA 1003
ORCA-1004

<URL> filtering policy settings configured.

high
Auto-remediable
ORCA 1004
ORCA-101

Bulk is marked as spam.

medium
Auto-remediable
ORCA 101
ORCA-102

Advanced Spam filter options are turned off.

medium
Auto-remediable
ORCA 102
ORCA-103

Outbound spam filter policy settings configured.

medium
Auto-remediable
ORCA 103405D 1.M.A
ORCA-104

High Confidence Phish action set to Quarantine message.

high
Auto-remediable
ORCA 104
ORCA-105

Safe Links Synchronous URL detonation is enabled.

medium
Auto-remediable
ORCA 105405D 1.L.A
ORCA-106

Quarantine retention period is 30 days.

medium
Auto-remediable
ORCA 106
ORCA-107

End-user spam notification is enabled.

low
Auto-remediable
ORCA 107
ORCA-108

DKIM signing is set up for all your custom domains.

medium
Auto-remediable
ORCA 108405D 1.M.A
ORCA-108.1

DNS Records have been set up to support DKIM.

medium
ORCA 108.1405D 1.M.A
ORCA-109

Senders are not being allow listed in an unsafe manner.

medium
Auto-remediable
ORCA 109405D 1.M.A
ORCA-110

Internal Sender notifications are disabled.

medium
Auto-remediable
ORCA 110
ORCA-111

Anti-phishing policy exists and EnableUnauthenticatedSender is true.

high
Auto-remediable
ORCA 111405D 1.M.A
ORCA-112

Anti-spoofing protection action is configured to Move message to the recipients' Junk Email folders in Anti-phishing policy.

medium
Auto-remediable
ORCA 112405D 1.M.A
ORCA-113

AllowClickThrough is disabled in Safe Links policies.

medium
Auto-remediable
ORCA 113405D 1.L.A
ORCA-114

No IP Allow Lists have been configured.

high
Auto-remediable
ORCA 114405D 1.M.A
ORCA-115

Mailbox intelligence based impersonation protection is enabled in anti-phishing policies.

medium
Auto-remediable
ORCA 115405D 1.M.A
ORCA-116

Mailbox intelligence based impersonation protection action set to move message to junk mail folder.

medium
Auto-remediable
ORCA 116405D 1.M.A
ORCA-118.1

Domains are not being allow listed in an unsafe manner in Anti-Spam Policies.

high
Auto-remediable
ORCA 118.1405D 1.M.A
ORCA-118.2

Domains are not being allow listed in an unsafe manner in Transport Rules.

high
Auto-remediable
ORCA 118.2405D 1.M.A
ORCA-118.3

Your own domains are not being allow listed in an unsafe manner in Anti-Spam Policies.

medium
Auto-remediable
ORCA 118.3405D 1.M.A
ORCA-118.4

Your own domains are not being allow listed in an unsafe manner in Transport Rules.

medium
Auto-remediable
ORCA 118.4405D 1.M.A
ORCA-120.1

Zero Hour Autopurge Enabled for Phish.

medium
Auto-remediable
ORCA 120.1
ORCA-120.2

Zero Hour Autopurge Enabled for Malware.

medium
Auto-remediable
ORCA 120.2
ORCA-120.3

Zero Hour Autopurge Enabled for Spam.

medium
Auto-remediable
ORCA 120.3
ORCA-121

Supported filter policy action used.

low
Auto-remediable
ORCA 121
ORCA-124

Safe attachments unknown malware response set to block messages.

high
Auto-remediable
ORCA 124405D 1.L.A
ORCA-139

Spam action set to move message to junk mail folder or quarantine.

low
Auto-remediable
ORCA 139
ORCA-140

High Confidence Spam action set to Quarantine message.

high
Auto-remediable
ORCA 140
ORCA-141

Bulk action set to Move message to Junk Email Folder.

medium
Auto-remediable
ORCA 141
ORCA-142

Phish action set to Quarantine message.

medium
Auto-remediable
ORCA 142
ORCA-156

Safe Links Policies are tracking when user clicks on safe links.

medium
Auto-remediable
ORCA 156405D 1.L.A
ORCA-158

Safe Attachments is enabled for SharePoint and Teams.

medium
Auto-remediable
ORCA 158405D 1.L.A
ORCA-179

Safe Links is enabled intra-organization.

medium
Auto-remediable
ORCA 179405D 1.L.A
ORCA-180

Anti-phishing policy exists and EnableSpoofIntelligence is true.

medium
Auto-remediable
ORCA 180405D 1.M.A
ORCA-189

Safe Attachments is not bypassed.

medium
Auto-remediable
ORCA 189405D 1.L.A
ORCA-189.2

Safe Links is not bypassed.

high
Auto-remediable
ORCA 189.2405D 1.L.A
ORCA-205

Common attachment type filter is enabled.

medium
Auto-remediable
ORCA 205405D 1.M.A
ORCA-220

Advanced Phish filter Threshold level is adequate.

medium
Auto-remediable
ORCA 220
ORCA-221

Mailbox intelligence is enabled in anti-phishing policies.

medium
Auto-remediable
ORCA 221405D 1.M.A
ORCA-222

Domain Impersonation action is set to move to Quarantine.

medium
Auto-remediable
ORCA 222405D 1.M.A
ORCA-223

User impersonation action is set to move to Quarantine.

high
Auto-remediable
ORCA 223405D 1.M.A
ORCA-225

Safe Documents is enabled for Office clients.

medium
Auto-remediable
ORCA 225
ORCA-226

Each domain has a Safe Link policy applied to it.

medium
Auto-remediable
ORCA 226405D 1.L.A
ORCA-227

Each domain has a Safe Attachments policy applied to it.

medium
Auto-remediable
ORCA 227405D 1.L.A
ORCA-228

No trusted senders in Anti-phishing policy.

high
Auto-remediable
ORCA 228405D 1.M.A
ORCA-229

No trusted domains in Anti-phishing policy.

medium
Auto-remediable
ORCA 229405D 1.M.A
ORCA-230

Each domain has a Anti-phishing policy applied to it, or the default policy is being used.

medium
Auto-remediable
ORCA 230405D 1.M.A
ORCA-231

Each domain has a anti-spam policy applied to it, or the default policy is being used.

medium
Auto-remediable
ORCA 231405D 1.M.A
ORCA-232

Each domain has a malware filter policy applied to it, or the default policy is being used.

high
Auto-remediable
ORCA 232
ORCA-233

Domains are pointed directly at EOP or enhanced filtering is used.

medium
ORCA 233
ORCA-233.1

Domains are pointed directly at EOP or enhanced filtering is configured on all default connectors.

medium
ORCA 233.1
ORCA-234

Click through is disabled for Safe Documents.

medium
Auto-remediable
ORCA 234
ORCA-235

SPF records is set up for all your custom domains.

medium
ORCA 235405D 1.M.A
ORCA-236

Safe Links is enabled for emails.

medium
Auto-remediable
ORCA 236405D 1.L.A
ORCA-237

Safe Links is enabled for teams messages.

medium
Auto-remediable
ORCA 237405D 1.L.A
ORCA-238

Safe Links is enabled for office documents.

medium
Auto-remediable
ORCA 238405D 1.L.A
ORCA-239

No exclusions for the built-in protection policies.

high
Auto-remediable
ORCA 239
ORCA-240

Outlook is configured to display external tags for external emails.

medium
Auto-remediable
ORCA 240
ORCA-241

Anti-phishing policy exists and EnableFirstContactSafetyTips is true.

medium
Auto-remediable
ORCA 241405D 1.M.A
ORCA-242

Important protection alerts responsible for AIR activities are enabled.

high
Auto-remediable
ORCA 242
ORCA-243

Authenticated Receive Chain is set up for domains not pointing to EOP/MDO, or all domains point to EOP/MDO.

medium
ORCA 243
ORCA-244

Policies are configured to honor sending domains DMARC.

medium
Auto-remediable
ORCA 244405D 1.M.A