ORCA Opti
Back to Insights

Insights

ORCA for Microsoft 365: what it checks, how to run it, and where it stops

ORCA is the free PowerShell tool that scores your Microsoft 365 email security. Here's how to run Get-ORCAReport, read the result, and what it misses.

Paige HarknessCo-Founder, Head of Product and Communications, ORCA Opti2 July 20264 min read

Here's something we didn't expect. People searching "ORCA 365" kept landing on us.

We're ORCA Opti. The ORCA most of them are after is a different animal: the Microsoft Defender for Office 365 Recommended Configuration Analyzer, a free PowerShell tool that scores your tenant's email security against Microsoft's own best practice. Same name, same instinct (know where your Microsoft 365 actually stands), different tool.

So rather than quietly take the traffic, we thought we'd be useful. If you've run Get-ORCAReport, watched it return "Standard: 61%", and quietly closed the tab, this one's for you.

What the ORCA 365 config analyzer checks

It reads your Exchange Online Protection and Defender for Office 365 settings, compares them to Microsoft's recommended baselines, and hands you an HTML report with a score.

It covers the email hygiene layer: anti-spam and anti-phishing policies, anti-spoofing and DKIM, Safe Links, Safe Attachments, zero-hour auto purge, the malware filter, transport rules, connectors and a handful of tenant settings. Where a setting is softer than Microsoft's "Standard" or "Strict" baseline, it flags it and tells you what good looks like.

It's built by Microsoft product managers, but it's a community project, not an official in-product feature. It's free, and it's genuinely handy.

How to run it

Three commands, assuming you have the Exchange Online management module and the "View-Only Configuration" role:

Install-Module ORCA
Connect-ExchangeOnline
Get-ORCAReport

It works through the checks, writes an HTML report to your AppData folder, and opens it in your browser. That's the whole job. No agents, nothing installed on endpoints, read-only.

How to read your score

You get a percentage against two baselines, Standard and Strict. Most tenants that have never been deliberately hardened land somewhere in the 50s to 70s the first time. That's normal. Don't panic at 61%.

Work top-down by impact, not by chasing 100%. The findings that matter are usually the same handful: anti-phishing thresholds set too low, Safe Links or Safe Attachments not fully on, DKIM not configured, ZAP switched off. Fix those, re-run the report, watch the number move. It's a satisfying afternoon.

Where the ORCA 365 config analyzer stops

This is the honest part, and it's really why we wrote this.

It is a one-off snapshot. You run it, you get a number, and then it forgets you exist. The day after you have fixed everything and hit a lovely green score, someone can flip a setting, an admin can add an over-permissive transport rule, a policy can quietly drift, and it has no idea until you remember to run it again. Configuration drift is where a lot of the real risk lives, and a point-in-time script can't see it.

It's also email-only. It says nothing about your identity posture (MFA coverage, legacy auth, conditional access), device compliance, external sharing in SharePoint and OneDrive, or anything outside Microsoft 365. Email is a big attack surface. It isn't the whole tenant.

And it's PowerShell. That's fine for you. It's less fine for the person who inherits your tenant, the auditor who wants evidence, or the board that wants a number they understand.

What we do (the honest version)

We're a vendor. You already knew that. So here's the straight version: Opti Cyber is the continuous, browser-based cousin of the ORCA 365 config analyzer.

Instead of a one-off email-security score, it watches your Microsoft 365 posture continuously (identity, email, sharing, devices, configuration), catches drift the moment a setting changes, maps what it finds to frameworks like ISO 27001, NIST CSF and the Essential Eight, and keeps the evidence so you are not reconstructing it the night before an audit. It extends across Azure, AWS and Google Cloud if you are hybrid. No PowerShell, nothing on endpoints.

It is not a replacement for running the ORCA 365 config analyzer once out of curiosity. It is what you want if you have decided you never want to manually re-run a config check again. Opti Cyber currently sits in Opti Core Premium.

The line to take upstairs

If you need to explain this to someone who does not care what a transport rule is: "We can check our Microsoft 365 security once with a free script, or monitor it continuously and have the evidence ready for audits and cyber insurance. The first is free and manual. The second runs itself."

Run the ORCA 365 config analyzer. It's good, and it's free. If you want a broader read without the PowerShell, our free Microsoft 365 security snapshot scores identity, email, sharing and monitoring in about two minutes, no sign-in required. And when you decide you never want the check to be a moment in time again, take a look at Opti Cyber.

Have a question? Let's talk.

Get in touch with the ORCA Opti team to see how governed, sovereign AI fits your organisation.

Join our mailing list

News and updates from ORCA Opti.