The short answer
Treat the connector as a new vendor, not a setting.
The connector lets Claude read your firm's email, files and Teams chats, but only what each person can already open. One consent from your firm's Global Administrator opens it to the whole firm, and Anthropic supports it on every Claude plan, personal accounts included. Anthropic processes what it reads, under Anthropic's terms, and keeps it with the chat. With write tools on, it can also send email and Teams messages as that person. None of this makes it unsafe. But your firm should first decide in writing: which people, which plan, read or write, and how long chats are kept.
Inside Copilot, or through the connector
The same Claude models can reach your firm's files two ways. Inside Copilot, Anthropic works for Microsoft. Through the connector, Anthropic is your firm's own vendor, or a staff member's.
| Question | Inside Copilot | Through the connector |
|---|---|---|
| How it is turned on | In the Microsoft 365 admin center. On by default for most commercial tenants outside the EU, EFTA and UK | A Global Administrator consents once for the whole firm. On Team and Enterprise, a Claude Owner also turns it on |
| Who can use it | Chosen users or security groups, in the same setting | Anyone at the firm who connects, unless the Entra apps require assignment or, on Team and Enterprise, an Owner restricts it |
| Which Claude plans | None. No Claude account is involved | Free, Pro, Max, Team and Enterprise |
| What it can read | What the user can open | What the user can open, acting as that user |
| What it can change | Copilot Cowork, which carries out tasks, stays off until an administrator turns it on | Read-only by default. With write tools on: email, calendar, SharePoint and OneDrive files, Teams messages |
| Contract | Microsoft's Product Terms and Data Protection Addendum, except opt-in "Data Retention" models | Anthropic's terms: commercial on Team and Enterprise, consumer on Free, Pro and Max |
| Training on firm data | Not used to train foundation models, Microsoft says | Commercial plans: not by default. Personal plans: each person's own setting |
| Where the content ends up | Processed by Anthropic, outside Microsoft's in-country commitments | Kept with the chat in Anthropic's app. Enterprise keeps chats until deleted unless a retention period is set |
| The record | Purview can search and retain Copilot interactions, once set up | Microsoft's audit log, per Anthropic, and Anthropic's own logs. Enterprise adds a Compliance API |
Where the data goes
Inside Copilot
- Claude runs as Microsoft's subprocessor
- Microsoft's terms, set in the Microsoft 365 admin center
- Record in Purview, once set up
Through the connector
- One consent covers the whole tenant
- Anthropic's terms, set by the Claude plan
- What it reads is kept with the chat
Connector or governed Copilot
Governed Microsoft 365 Copilot is Copilot that your firm has set up, not just switched on. Each license goes to a named person. Your administrator sets retention and data loss rules in Purview, Microsoft's compliance settings. Each outside AI provider is on or off because someone at your firm decided. Against the connector, on the questions a regulated firm gets asked, governed Copilot has the edge on five of six. The sixth, where the model runs, is a tie, because neither vendor commits to a location today.
| Question | Governed Copilot | Claude connector | Edge |
|---|---|---|---|
| Contract | Microsoft's Product Terms and Data Protection Addendum, the contract the firm's Microsoft 365 already runs under | Anthropic's. Commercial terms on Team and Enterprise, consumer terms on Free, Pro and Max | Governed Copilot |
| Which accounts | The firm's Microsoft 365 Copilot licenses, assigned by name | Any Claude plan, personal ones included. Entra assignment limits who connects, not which Claude plan they use | Governed Copilot |
| Training on firm data | Not used to train foundation models, Microsoft says | Commercial plans: not by default. Personal plans: each person's own setting | Governed Copilot |
| Where it is stored | In the user's Exchange Online mailbox, in your firm's default geography. Microsoft commits to this for U.S. tenants | With the chat, in Anthropic's app, for as long as the chat is kept. Anthropic documents no storage location setting for its Claude plans | Governed Copilot |
| Where the model runs | Microsoft's cloud, not your firm's Microsoft 365: in region first, other regions under load. U.S. in-country processing expected by the end of 2026 | Anthropic's infrastructure. Anthropic documents no processing location setting for its Claude plans; its U.S.-only setting is for its API | Neither commits |
| The record | Purview can search, retain and apply data loss rules to Copilot interactions, once set up | Microsoft's audit log of what it read, and Anthropic's own logs. Enterprise adds a Compliance API | Governed Copilot |
When the connector fits. Use governed Copilot for client work by default. Treat the connector as an exception your firm grants on purpose, to named people. It fits only when all five of these are true:
- The person connects from your firm's Team or Enterprise plan, not a personal one.
- In Microsoft Entra, the sign-in and access settings for Microsoft 365, both of the connector's apps are set to require assignment. That means only people assigned to them can connect, and that person is one of them.
- It can only read, unless someone has decided separately to let it write.
- The work holds no tax return information. Or, if it does, each client it belongs to has given consent, and your counsel has seen the storage and processing facts above.
- Your firm knows how long chats are kept, and on Enterprise has set a retention period.
If any of the five is not true, do that work in governed Copilot. Tax return information still needs each client's consent there, until Microsoft commits to U.S.-only processing and your firm can show who reaches the data. There, your firm already has Microsoft's contract. For U.S. tenants, Microsoft commits to storing prompts and responses in your firm's default geography. And once set up, Purview can search and keep each Copilot interaction.
Before anyone consents
A Global Administrator can give consent, Microsoft's word for approving the app for the whole firm, in a few clicks. Before that, your firm should be able to answer five questions in writing. If the connector's apps already appear in Entra under Enterprise applications, your firm has most likely consented already. The questions still apply.
- Which staff may connect, and is the app limited to them?
- From which Claude plan: the firm's, or anyone's?
- Read only, or can it send and edit?
- How long are chats kept, and who can see them?
- Where is the record of what it read?
If the answers are not written down, the consent is not a decision yet. It is a default.
The detail
The detail, in four parts
01One consent, every plan
+
Anthropic publishes the connector as two apps in Microsoft Entra. Your administrator finds them in the Entra admin center, under Enterprise applications, as M365 MCP Client for Claude and M365 MCP Server for Claude. Before anyone at your firm can connect, a Global Administrator grants consent once, for the whole firm.
On Team and Enterprise plans, an Owner in Claude also has to turn the connector on for the organization. On Free, Pro and Max plans, Anthropic says, "no organization-level setup is needed." For those plans, the Global Administrator's one consent is all it takes.
Anthropic's documentation describes one pair of Entra apps for the connector on claude.ai, the same for every plan. On that reading, the consent your firm gives for its own Claude plan also lets a staff member connect a personal account. The plan a person connects from decides which terms apply: Anthropic's commercial terms on Team and Enterprise, its consumer terms on Free, Pro and Max.
That difference matters. Under Anthropic's consumer terms, each person chooses whether their chats are used to improve its models. Chats used that way are kept in de-identified form for up to five years. Under its commercial terms, Anthropic does not use customer data for training by default.
Limiting who can connect. In Entra, an administrator can set an app to require assignment, so only the people assigned to it can use it. Microsoft's documentation is plain about the effect: "Users and services attempting to access the application or services need to be assigned to the application, or they won't be able to sign-in or obtain an access token." Anthropic's security guide points to the same setting, on both of the connector's apps. It also points to Conditional Access policies, Microsoft's sign-in rules, applied to chosen security groups.
Assignment limits which people can connect. It does not control which Claude plan they connect from. That belongs in your firm's written AI policy.
02What it reads, and what it can change
+
Anthropic describes every permission as delegated, meaning Claude acts as the signed-in person. In Anthropic's words: "Claude acts on behalf of users and can only access and change content that you already have permission to access and change in Microsoft 365." It reads Word, Excel, PowerPoint, PDF and plain-text files, email threads, Teams chats and channel messages, and meeting information.
It reads only when asked. Anthropic says the connector "doesn't run background searches" and "doesn't cache file content."
Reading only what each person can open cuts both ways. The connector reads everything the person can open, and in most small firms that is more than anyone intended. So have your administrator check who can open what first, whichever assistant reads the files. We covered why staff can open more than they should in Copilot Does Not Leak. It Reveals.
Write tools. Permissions are read-only by default. With write tools on, Claude acts as the user. It can send and manage email; create, update and delete calendar events; create and update files in SharePoint and OneDrive; and send Teams messages. Turning them on takes two steps. First, if your firm consented before the write permissions were added, an Entra administrator approves them. Then a Claude administrator turns on write actions for everyone or, on Enterprise, for chosen users.
An assistant that can send email from a partner's mailbox is a different risk from one that can read it. Decide the two separately.
03Where the content goes
+
Anthropic says a firm's "Microsoft 365 documents, emails, and files remain in your tenant," and that the connector fetches them only while answering a question. Anthropic then processes what it fetched to answer that question. Anthropic's security guide adds: "Tool call results from the connector that are part of stored chats are retained." In plain terms, the part Claude read stays with the conversation, in Anthropic's app, for as long as the conversation is kept.
How long that is depends on the plan. On Enterprise, Anthropic says chats are retained "indefinitely unless a custom retention period is set," and an Owner can set a period of 30 days or more. On a commercial plan, when a person deletes a conversation, Anthropic says it leaves their chat history immediately and is deleted from Anthropic's back-end systems within 30 days.
For a tax firm, this is the §7216 question from our Copilot vs Claude brief in a different shape. If return information is pulled into a chat, Anthropic processes and keeps it under Anthropic's terms, not Microsoft's. Anthropic documents a U.S.-only processing setting for its API, the service developers build on. It describes none for its Team and Enterprise plans. Claremont's position is the same as for Copilot: return information goes in only with each client's consent, and for Form 1040 clients the Social Security number stays out even with consent. Whether a particular disclosure needs consent is for your firm's counsel to decide. Put these facts in front of counsel before anyone connects a mailbox full of returns.
04Where you can limit it
+
In Microsoft Entra. An administrator can withdraw the consent, in part or in full. The connector's two apps can require assignment, so only named users or groups can sign in to them. Anthropic's guide supports Conditional Access sign-in rules. It recommends a separate multifactor policy if your firm's existing one does not apply to the connector's sign-in.
In Claude. On Team and Enterprise, Owners turn the connector on and decide whether write actions are on. They can also limit which members use it, or switch off specific permissions. On Enterprise, except for public sector organizations, Anthropic's Compliance API lets your firm's IT pull activity feeds, chat data, file content and audit log events out of Claude.
The record. The connector's Microsoft Graph calls, its requests to Microsoft 365, "are logged in your organization's Microsoft 365 audit log," Anthropic says. Anthropic also logs sign-ins and each tool the connector runs, on its own side. Do not assume Purview's rules for Copilot, such as its data loss rules, cover the connector. Microsoft documents them for Microsoft 365 Copilot and Copilot Chat. Nothing in that documentation extends them to another vendor's app. Neither Anthropic's setup guide nor its security guide mentions sensitivity labels, the labels that mark confidential files.
Sources
§Sources+
Anthropic
- Claude Docs: Microsoft 365 connector
- Claude Help Center: Set up the Microsoft 365 connector
- Claude Help Center: Connect to Microsoft 365
- Claude Help Center: Microsoft 365 connector security guide
- Anthropic Privacy Center: How long do you store my organization's data? updated 2026-07-01
- Anthropic Privacy Center: Configure custom data retention controls for Enterprise plans
- Anthropic Privacy Center: How long do you store my data? updated 2026-07-01
- Anthropic: Updates to Consumer Terms and Privacy Policy
- Anthropic: Regional compliance
- Claude Platform Docs: Data residency
- Claude Help Center: Access the Compliance API
Microsoft
- Microsoft Learn: Restrict a Microsoft Entra app to a set of users page updated 2025-07-08
- Microsoft Learn: Anthropic models in Microsoft Online Services page updated 2026-09-18
- Microsoft Learn: Microsoft Purview DLP for Microsoft 365 Copilot and Copilot Chat page updated 2026-09-17
- Microsoft Learn: data, privacy and security for Copilot page updated 2026-08-18
- Microsoft 365 blog: Copilot Cowork is now generally available posted 2026-06-16
- Microsoft 365 blog: in-country data processing for Copilot posted 2025-11-04, editor's note 2026-04-03
Claremont Security sets up governed Microsoft Copilot for regulated firms, including the decision on outside AI apps like this one: which people, which plan, read or write, and the record. To see where a firm's data can travel, try the AI Exposure Check. It is free and needs no account: claremontsecurity.com/ai-exposure
claremontsecurity.com/insights/claude-microsoft-365-connector
