Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Inconsistent presentation, different results in two runs, unclear scoring. #265

Open
CW-RKR opened this issue Oct 25, 2023 · 1 comment
Open
Assignees
Labels
question Further information is requested

Comments

@CW-RKR
Copy link

CW-RKR commented Oct 25, 2023

When I run ORCA against the same tenant several times in quick succession, I get the results in different sorting and sometimes with different results. Although no one has changed any settings in the tenant or the security settings in the meantime.
Run 1
image

Run 2
image

1: Why does it say 'Disabled' behind the entry if it is not 'Disabled' at all?

2: The names of the policies sometimes differ in the ORCA report and in the security portal. Why?

3: If a policy is 'Disabled', its setting still counts (usually positively) towards the score. Why is that? Why are these entries not excluded?

Why are the numbers behind the 'Strict Preset Security Policy' settings and the 'Standard Preset Security Policy' setting? And why are some policies (with different numbers) listed several times, although they only exist once in the tenant?

image

Regarding point 1:
image

Regarding point 2:
image

@cammurray
Copy link
Owner

cammurray commented Feb 21, 2024

Interesting. @CW-RKR are you able to share the two reports with me? My email is [email protected]

Sorry for the delay in response, was off for a bit over christmas.

@cammurray cammurray self-assigned this Feb 21, 2024
@cammurray cammurray added the question Further information is requested label Feb 21, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
question Further information is requested
Projects
None yet
Development

No branches or pull requests

2 participants