Skip to main content
Version: 2.1.1-preview

ORCA.109 - Senders are not being allow listed in an unsafe manner.

Overview

Emails coming from allow listed senders bypass several layers of protection within Exchange Online Protection. If senders are allow listed, they are open to being spoofed from malicious actors.

Remediation action

Remove allow listing on senders.

Test Metadata

FieldValue
Test IDORCA.109
SeverityMedium
SuiteORCA
CategoryEXO
PowerShell testTest-ORCA109
TagsEXO, ORCA, ORCA.109

Source

  • Pester test: tests/orca/Test-ORCA109.Tests.ps1
  • PowerShell source: powershell/public/orca/Test-ORCA109.ps1