Skip to main content
Version: 2.1.0

ORCA.226 - Each domain has a Safe Link policy applied to it.

Overview

Microsoft Defender for Office 365 Safe Links policies are applied using rules. The recipient domain condition is the most effective way of applying the Safe Links policy, ensuring no users are left without protection. If polices are applied using group membership make sure you cover all users through this method. Applying polices this way can be challenging, users may left unprotected if group memberships are not accurate and up to date. It is important not to rely on the 'built-in' Safe Links policy, as this policy only applies the minimum level of protections and should serve as a catch-all.

Remediation action

Apply a Safe Links policy to every domain.

Test Metadata

FieldValue
Test IDORCA.226
SeverityMedium
SuiteORCA
CategoryEXO
PowerShell testTest-ORCA226
TagsEXO, ORCA, ORCA.226

Source

  • Pester test: tests/orca/Test-ORCA226.Tests.ps1
  • PowerShell source: powershell/public/orca/Test-ORCA226.ps1