当前位置:网站首页 > 更多 > 玩电脑 > 正文

[玩转系统] Office 365 推荐配置分析器

作者:精品下载站 日期:2024-12-14 03:35:25 浏览:15 分类:玩电脑

Office 365 推荐配置分析器


在本文中,您将了解如何提高 Exchange Online - Office 365 中的安全性。我们将使用 Microsoft Defender for Office 365 推荐配置分析器 (ORCA) 工具并创建 ORCA 报告。我们还将了解 Microsoft 365 Defender 门户中的配置分析器。

当您拥有 Exchange Online 或 Microsoft 365 时,大多数人认为他们无需再执行任何操作。一切都在云端,微软将完成剩下的工作。我们很遗憾地告诉你,但这是完全错误的。您需要确定当前配置中的问题并进行改进以提高安全性。

Office 365 推荐配置分析器 (ORCA)

ORCA 是一份可以在 Microsoft 365 环境中运行的报告,突出显示可能影响 Microsoft Defender for Office 365(以前称为 Office 365 高级威胁防护)体验的已知配置问题和改进。

配置分析器分析以下类型的策略:

  • Exchange Online Protection (EOP) 策略:这包括具有 Exchange Online 邮箱的 Microsoft 365 组织和没有 Exchange Online 邮箱的独立 EOP 组织。
  • Microsoft Defender for Office 365 策略:这包括拥有 Microsoft 365 E5 或 Defender for Office 365 附加订阅的组织。

您可以在没有 Microsoft Defender for Office 365 的情况下运行 ORCA 报告,但检查次数会较少。始终从 PowerShell 库验证最新的 ORCA 版本。

安装 ORCA 模块

以管理员身份启动 Windows PowerShell。

运行 Install-Module ORCA cmdlet 以安装 ORCA PowerShell 模块。

Install-Module ORCA -Force

验证您是否使用 Get-InstalledModule cmdlet 成功安装了 ORCA 模块。

Get-InstalledModule -Name ORCA | ft -AutoSize

输出显示。

Version Name Repository Description
------- ---- ---------- -----------
2.8.1   ORCA PSGallery  The Microsoft Defender for Office 365 Recommended Configuration Analyzer (ORCA) Modul

获取 ORCA 报告

运行 Get-ORCAReport cmdlet。

Get-ORCAReport

注意:如果您没有安装 Exchange Online PowerShell 模块,它会要求您安装。

将出现一个窗口,要求您提供全局管理员凭据。

[玩转系统] Office 365 推荐配置分析器

让它分析租户并进行推荐检查。

08/03/2023 13:10:38 Performing ORCA Version check...
08/03/2023 13:10:44 Connecting to Exchange Online (Modern Module)..
08/03/2023 13:10:48 Getting Anti-Spam Settings
08/03/2023 13:10:48 Getting Tenant Settings
08/03/2023 13:10:49 Getting MDO Preset Policy Settings
08/03/2023 13:10:49 Getting Protection Alerts
08/03/2023 13:10:51 Getting EOP Preset Policy Settings
08/03/2023 13:10:52 Getting Quarantine Policy Settings
08/03/2023 13:10:54 Getting Anti Phish Settings
08/03/2023 13:10:54 Getting Anti-Malware Settings
08/03/2023 13:10:54 Getting Transport Rules
08/03/2023 13:10:55 Getting MDO Policies
08/03/2023 13:10:55 Getting Accepted Domains
08/03/2023 13:10:55 Getting DKIM Configuration
08/03/2023 13:10:56 Getting Connectors
08/03/2023 13:10:56 Getting Outlook External Settings
08/03/2023 13:10:56 Getting MX Reports for all domains
08/03/2023 13:11:09 Determining applied policy states
08/03/2023 13:11:09 Analysis - Anti-Spam Policies - Domain Allowlist
08/03/2023 13:11:09 Analysis - Anti-Spam Policies - Spam Action
08/03/2023 13:11:09 Analysis - Anti-Spam Policies - Domain Allowlisting
08/03/2023 13:11:09 Analysis - Anti-Spam Policies - Allowed Senders
08/03/2023 13:11:09 Analysis - Anti-Spam Policies - IP Allow Lists
08/03/2023 13:11:09 Analysis - Anti-Spam Policies - Safety Tips
08/03/2023 13:11:09 Skipping - Safety Tips - No longer part of Anti-Spam Policies
08/03/2023 13:11:09 Analysis - Anti-Spam Policies - Anti-Spam Policy Rules
08/03/2023 13:11:09 Analysis - Anti-Spam Policies - Phish Action
08/03/2023 13:11:09 Analysis - Anti-Spam Policies - High Confidence Spam Action
08/03/2023 13:11:09 Analysis - Anti-Spam Policies - Bulk Action
08/03/2023 13:11:09 Analysis - Anti-Spam Policies - Mark Bulk as Spam
08/03/2023 13:11:10 Analysis - Anti-Spam Policies - High Confidence Phish Action
08/03/2023 13:11:10 Analysis - Anti-Spam Policies - Quarantine retention period
08/03/2023 13:11:10 Analysis - Anti-Spam Policies - Outbound spam filter policy settings
08/03/2023 13:11:10 Analysis - Anti-Spam Policies - Advanced Spam Filter (ASF)
08/03/2023 13:11:10 Analysis - Anti-Spam Policies - Bulk Complaint Level
08/03/2023 13:11:10 Analysis - Connectors - Enhanced Filtering Configuration
08/03/2023 13:11:10 Analysis - Connectors - Domains
08/03/2023 13:11:10 Analysis - DKIM - DNS Records
08/03/2023 13:11:11 Analysis - DKIM - Signing Configuration
08/03/2023 13:11:11 Analysis - Malware Filter Policy - Common Attachment Type Filter
08/03/2023 13:11:11 Analysis - Malware Filter Policy - Malware Filter Policy Policy Rules
08/03/2023 13:11:11 Analysis - Malware Filter Policy - Internal Sender Notifications
08/03/2023 13:11:11 Analysis - Microsoft Defender for Office 365 Alerts - Protection Alerts
08/03/2023 13:11:11 Analysis - Microsoft Defender for Office 365 Policies - Anti-phishing trusted senders
08/03/2023 13:11:11 Analysis - Microsoft Defender for Office 365 Policies - Safe Attachments Policy Rules
08/03/2023 13:11:11 Analysis - Microsoft Defender for Office 365 Policies - Anti-phishing Rules
08/03/2023 13:11:11 Analysis - Microsoft Defender for Office 365 Policies - Anti-phishing trusted domains
08/03/2023 13:11:11 Analysis - Microsoft Defender for Office 365 Policies - Safe Links Policy Rules
08/03/2023 13:11:12 Analysis - Microsoft Defender for Office 365 Policies - User Impersonation Action
08/03/2023 13:11:12 Analysis - Microsoft Defender for Office 365 Policies - Intra-organization Safe Links
08/03/2023 13:11:12 Analysis - Microsoft Defender for Office 365 Policies - Safe Documents for Office clients
08/03/2023 13:11:12 Analysis - Microsoft Defender for Office 365 Policies - Similar Users Safety Tips
08/03/2023 13:11:12 Analysis - Microsoft Defender for Office 365 Policies - Mailbox Intelligence Protection
08/03/2023 13:11:12 Analysis - Microsoft Defender for Office 365 Policies - Safe Links protections for links in office documents
08/03/2023 13:11:12 Analysis - Microsoft Defender for Office 365 Policies - Safe Links protections for links in teams messages
08/03/2023 13:11:12 Analysis - Microsoft Defender for Office 365 Policies - First Contact Safety Tip
08/03/2023 13:11:12 Analysis - Microsoft Defender for Office 365 Policies - Built-in Protection
08/03/2023 13:11:12 Analysis - Microsoft Defender for Office 365 Policies - Safe Links protections for links in email
08/03/2023 13:11:12 Analysis - Microsoft Defender for Office 365 Policies - Anti-spoofing protection action
08/03/2023 13:11:12 Analysis - Microsoft Defender for Office 365 Policies - Do not let users click through safe links
08/03/2023 13:11:12 Analysis - Microsoft Defender for Office 365 Policies - Do not let users click through Safe Documents for Office clients
08/03/2023 13:11:12 Analysis - Microsoft Defender for Office 365 Policies - Unauthenticated Sender (tagging)
08/03/2023 13:11:12 Analysis - Microsoft Defender for Office 365 Policies - Mailbox Intelligence Enabled
08/03/2023 13:11:12 Analysis - Microsoft Defender for Office 365 Policies - Safe Links Synchronous URL detonation
08/03/2023 13:11:12 Analysis - Microsoft Defender for Office 365 Policies - Similar Domains Safety Tips
08/03/2023 13:11:12 Analysis - Microsoft Defender for Office 365 Policies - Safe Links Tracking
08/03/2023 13:11:12 Analysis - Microsoft Defender for Office 365 Policies - Domain Impersonation Action
08/03/2023 13:11:12 Analysis - Microsoft Defender for Office 365 Policies - Unusual Characters Safety Tips
08/03/2023 13:11:12 Analysis - Microsoft Defender for Office 365 Policies - Safe attachments unknown malware response
08/03/2023 13:11:12 Analysis - Microsoft Defender for Office 365 Policies - Safe Attachments SharePoint and Teams
08/03/2023 13:11:13 Analysis - Microsoft Defender for Office 365 Policies - Safe Links Allow Listing
08/03/2023 13:11:13 Analysis - Microsoft Defender for Office 365 Policies - Mailbox Intelligence Protection Action
08/03/2023 13:11:13 Analysis - Microsoft Defender for Office 365 Policies - Safe Attachments Allow listing
08/03/2023 13:11:13 Analysis - Microsoft Defender for Office 365 Policies - Anti-spoofing protection
08/03/2023 13:11:13 Analysis - Microsoft Defender for Office 365 Policies - Advanced Phishing Threshold Level
08/03/2023 13:11:13 Analysis - Outlook - External Tags
08/03/2023 13:11:13 Analysis - Quarantine Policies - End-user Spam notifications
08/03/2023 13:11:13 Analysis - SPF - SPF Records
08/03/2023 13:11:13 Analysis - Tenant Settings - Unified Audit Log
08/03/2023 13:11:13 Analysis - Transport Rules - Domain Allow Listing
08/03/2023 13:11:13 Analysis - Transport Rules - Domain Allow Listing
08/03/2023 13:11:13 Analysis - Zero Hour Autopurge - Zero Hour Autopurge Enabled for Phish
08/03/2023 13:11:13 Analysis - Zero Hour Autopurge - Zero Hour Autopurge Enabled for Malware
08/03/2023 13:11:13 Analysis - Zero Hour Autopurge - Supported filter policy action
08/03/2023 13:11:13 Analysis - Zero Hour Autopurge - Zero Hour Autopurge Enabled for Spam
08/03/2023 13:11:14 Generating Output
08/03/2023 13:11:14 Output - HTML
08/03/2023 13:11:20 Complete! Output is in C:\Users\administrator.EXOIP\AppData\Local\Microsoft\ORCA\ORCA-exoip365-202308031311.html

经过上述检查后,将生成 HTML 报告并导出到 AppData 文件夹。在下一步中,我们将查看 ORCA HTML 报告。

ORCA 报告详细信息

默认情况下,HTML 报告将在您的默认浏览器中打开。我们注意到的第一件事是顶部的红色块。如果租户中没有 Microsoft Defender for Office 365,您将会看到这一点。如果没有显示,则意味着您拥有它,并且 ORCA 会执行额外的检查。

注意:在 Microsoft 365 租户中使用 Microsoft Defender for Office 365 以获得最大安全性。

[玩转系统] Office 365 推荐配置分析器

这是 Microsoft Defender for Office 365 可用时的外观。

[玩转系统] Office 365 推荐配置分析器

向下滚动到摘要并检查 ORCA 报告分析的部分。

[玩转系统] Office 365 推荐配置分析器

滚动到需要改进的部分之一。在此示例中,我们将了解反垃圾邮件策略

出站垃圾邮件过滤器策略设置有 4 个设置,其当前值不推荐,建议我们改进它。

在每个部分下,您可以找到有关推荐设置的更多信息。单击链接将打开 Microsoft 技术文档页面。最后一个链接将直接带您进入要配置的设置,这非常好。

[玩转系统] Office 365 推荐配置分析器

在下一步中,我们将查看 Office 365 推荐配置分析器,但这次是在 Microsoft 365 Defender 门户中。那是因为微软确实在其中添加了配置分析器。

Microsoft 365 Defender 配置分析器

配置分析器可以帮助识别当前配置中的问题,并帮助改进策略以提高安全性。

按照以下步骤转到 Microsoft 365 Defender 门户中的配置分析器:

  1. 登录 Microsoft 365 安全中心
  2. 展开电子邮件和协作
  3. 转到政策和规则 > 威胁策略
  4. 单击配置分析器

[玩转系统] Office 365 推荐配置分析器

标准建议

标准建议显示 18 条建议。我们可以选择每个建议并点击应用建议来改进策略。

用作基准的标准和严格策略设置值在 EOP 和 Microsoft Defender for Office 365 安全的建议设置中进行了描述。

[玩转系统] Office 365 推荐配置分析器

严格建议

严格建议总共显示 21 条建议。

[玩转系统] Office 365 推荐配置分析器

如果每个组织想要通过严格或标准的建议来改进策略,则取决于每个组织。

配置分析器显示不同的建议

ORCA 报告显示的建议与 Microsoft 365 门户中的配置分析器不同。为什么不相似呢?这是因为 ORCA 是由 Microsoft 的产品经理开发的,它不是 Microsoft 的官方实用程序。对于官方产品内配置分析,请使用门户中的 Microsoft 365 Defender 配置分析器。

遵循最新的 ORCA 报告建议,一切就都准备好了。配置分析器工具建议是否可以帮助您改进 Microsoft 365 租户?

了解更多:Microsoft Exchange Server 漏洞检查 »

结论

您了解了如何使用配置分析器检查和配置 Office 365 安全建议。 ORCA 报告将为您提供比安全门户更多的建议。此外,该报告还可以更轻松地访问 Microsoft 技术文档页面。

我建议现在使用这两种配置分析器。如果您只想按一个按钮,请通过 Microsoft 365 Defender 门户采用更改。如果要调整设置,请执行 Microsoft 技术文档中概述的步骤,您可以在每个部分下的 ORCA 报告中找到这些步骤。

您喜欢这篇文章吗?您可能还喜欢修复 Office 365 中的 Winmail.dat 附件。不要忘记关注我们并分享这篇文章。

您需要 登录账户 后才能发表评论

取消回复欢迎 发表评论:

关灯