Skip to main content
Version: 2.1.1-preview

ORCA.232 - Each domain has a malware filter policy applied to it, or the default policy is being used.

Overview​

Exchange Online Protection malware filter policies are applied using rules. The default policy applies in the absence of a custom policy. When creating custom policies, there may be duplication of settings and depending on the rules and priority, some policies or settings may not even apply. It's important in this circumstance to check that the desired settings are applied to the right users.

Remediation action​

Check your malware filter policies for duplicate rules. Some policies and settings may not be applying.

Test Metadata​

FieldValue
Test IDORCA.232
SeverityHigh
SuiteORCA
CategoryEXO
PowerShell testTest-ORCA232
TagsEXO, ORCA, ORCA.232

Source​

  • Pester test: tests/orca/Test-ORCA232.Tests.ps1
  • PowerShell source: powershell/public/orca/Test-ORCA232.ps1