The short answer

Treat the connector as a new vendor, not a setting.

The connector lets Claude read your firm's email, files and Teams chats, but only what each person can already open. One consent from your firm's Global Administrator opens it to the whole firm, and Anthropic supports it on every Claude plan, personal accounts included. Anthropic processes what it reads, under Anthropic's terms, and keeps it with the chat. With write tools on, it can also send email and Teams messages as that person. None of this makes it unsafe. But your firm should first decide in writing: which people, which plan, read or write, and how long chats are kept.

Inside Copilot, or through the connector

The same Claude models can reach your firm's files two ways. Inside Copilot, Anthropic works for Microsoft. Through the connector, Anthropic is your firm's own vendor, or a staff member's.

QuestionInside CopilotThrough the connector
How it is turned onIn the Microsoft 365 admin center. On by default for most commercial tenants outside the EU, EFTA and UKA Global Administrator consents once for the whole firm. On Team and Enterprise, a Claude Owner also turns it on
Who can use itChosen users or security groups, in the same settingAnyone at the firm who connects, unless the Entra apps require assignment or, on Team and Enterprise, an Owner restricts it
Which Claude plansNone. No Claude account is involvedFree, Pro, Max, Team and Enterprise
What it can readWhat the user can openWhat the user can open, acting as that user
What it can changeCopilot Cowork, which carries out tasks, stays off until an administrator turns it onRead-only by default. With write tools on: email, calendar, SharePoint and OneDrive files, Teams messages
ContractMicrosoft's Product Terms and Data Protection Addendum, except opt-in "Data Retention" modelsAnthropic's terms: commercial on Team and Enterprise, consumer on Free, Pro and Max
Training on firm dataNot used to train foundation models, Microsoft saysCommercial plans: not by default. Personal plans: each person's own setting
Where the content ends upProcessed by Anthropic, outside Microsoft's in-country commitmentsKept with the chat in Anthropic's app. Enterprise keeps chats until deleted unless a retention period is set
The recordPurview can search and retain Copilot interactions, once set upMicrosoft's audit log, per Anthropic, and Anthropic's own logs. Enterprise adds a Compliance API
Checked against Microsoft's and Anthropic's own documentation. The detail and every source are further down the page.

Where the data goes

Inside Copilot

  • Claude runs as Microsoft's subprocessor
  • Microsoft's terms, set in the Microsoft 365 admin center
  • Record in Purview, once set up
Claude inside CopilotCopilot reads what the person can open and sends work to Claude, run by Anthropic as a Microsoft subprocessor under Microsoft's terms. Copilot interactions can be recorded in Purview once that is set up.Microsoft 365AnthropicWhat the personcan openCopilotClauderun by AnthropicMicrosoft'ssubprocessor, underMicrosoft's termsRecordPurviewCopilot interactions, once set up

Through the connector

  • One consent covers the whole tenant
  • Anthropic's terms, set by the Claude plan
  • What it reads is kept with the chat
Claude through the connectorOne tenant consent lets Anthropic's Claude app read what the person can open, under Anthropic's terms for the person's Claude plan. What it reads is kept with the chat. The record sits in Microsoft's audit log and Anthropic's own logs.Microsoft 365AnthropicWhat the personcan openone tenantconsentClaude apprun by AnthropicChat historykept with the chatRecordTwo placesMicrosoft's audit log, Anthropic's logs

Connector or governed Copilot

Governed Microsoft 365 Copilot is Copilot that your firm has set up, not just switched on. Each license goes to a named person. Your administrator sets retention and data loss rules in Purview, Microsoft's compliance settings. Each outside AI provider is on or off because someone at your firm decided. Against the connector, on the questions a regulated firm gets asked, governed Copilot has the edge on five of six. The sixth, where the model runs, is a tie, because neither vendor commits to a location today.

QuestionGoverned CopilotClaude connectorEdge
ContractMicrosoft's Product Terms and Data Protection Addendum, the contract the firm's Microsoft 365 already runs underAnthropic's. Commercial terms on Team and Enterprise, consumer terms on Free, Pro and MaxGoverned Copilot
Which accountsThe firm's Microsoft 365 Copilot licenses, assigned by nameAny Claude plan, personal ones included. Entra assignment limits who connects, not which Claude plan they useGoverned Copilot
Training on firm dataNot used to train foundation models, Microsoft saysCommercial plans: not by default. Personal plans: each person's own settingGoverned Copilot
Where it is storedIn the user's Exchange Online mailbox, in your firm's default geography. Microsoft commits to this for U.S. tenantsWith the chat, in Anthropic's app, for as long as the chat is kept. Anthropic documents no storage location setting for its Claude plansGoverned Copilot
Where the model runsMicrosoft's cloud, not your firm's Microsoft 365: in region first, other regions under load. U.S. in-country processing expected by the end of 2026Anthropic's infrastructure. Anthropic documents no processing location setting for its Claude plans; its U.S.-only setting is for its APINeither commits
The recordPurview can search, retain and apply data loss rules to Copilot interactions, once set upMicrosoft's audit log of what it read, and Anthropic's own logs. Enterprise adds a Compliance APIGoverned Copilot
Checked against Microsoft's and Anthropic's own documentation. Sources are at the foot of the page.

When the connector fits. Use governed Copilot for client work by default. Treat the connector as an exception your firm grants on purpose, to named people. It fits only when all five of these are true:

  1. The person connects from your firm's Team or Enterprise plan, not a personal one.
  2. In Microsoft Entra, the sign-in and access settings for Microsoft 365, both of the connector's apps are set to require assignment. That means only people assigned to them can connect, and that person is one of them.
  3. It can only read, unless someone has decided separately to let it write.
  4. The work holds no tax return information. Or, if it does, each client it belongs to has given consent, and your counsel has seen the storage and processing facts above.
  5. Your firm knows how long chats are kept, and on Enterprise has set a retention period.

If any of the five is not true, do that work in governed Copilot. Tax return information still needs each client's consent there, until Microsoft commits to U.S.-only processing and your firm can show who reaches the data. There, your firm already has Microsoft's contract. For U.S. tenants, Microsoft commits to storing prompts and responses in your firm's default geography. And once set up, Purview can search and keep each Copilot interaction.

Before anyone consents

A Global Administrator can give consent, Microsoft's word for approving the app for the whole firm, in a few clicks. Before that, your firm should be able to answer five questions in writing. If the connector's apps already appear in Entra under Enterprise applications, your firm has most likely consented already. The questions still apply.

  1. Which staff may connect, and is the app limited to them?
  2. From which Claude plan: the firm's, or anyone's?
  3. Read only, or can it send and edit?
  4. How long are chats kept, and who can see them?
  5. Where is the record of what it read?

If the answers are not written down, the consent is not a decision yet. It is a default.

The detail

The detail, in four parts

02

What it reads, and what it can change

+

Anthropic describes every permission as delegated, meaning Claude acts as the signed-in person. In Anthropic's words: "Claude acts on behalf of users and can only access and change content that you already have permission to access and change in Microsoft 365." It reads Word, Excel, PowerPoint, PDF and plain-text files, email threads, Teams chats and channel messages, and meeting information.

It reads only when asked. Anthropic says the connector "doesn't run background searches" and "doesn't cache file content."

Reading only what each person can open cuts both ways. The connector reads everything the person can open, and in most small firms that is more than anyone intended. So have your administrator check who can open what first, whichever assistant reads the files. We covered why staff can open more than they should in Copilot Does Not Leak. It Reveals.

Write tools. Permissions are read-only by default. With write tools on, Claude acts as the user. It can send and manage email; create, update and delete calendar events; create and update files in SharePoint and OneDrive; and send Teams messages. Turning them on takes two steps. First, if your firm consented before the write permissions were added, an Entra administrator approves them. Then a Claude administrator turns on write actions for everyone or, on Enterprise, for chosen users.

An assistant that can send email from a partner's mailbox is a different risk from one that can read it. Decide the two separately.

03

Where the content goes

+

Anthropic says a firm's "Microsoft 365 documents, emails, and files remain in your tenant," and that the connector fetches them only while answering a question. Anthropic then processes what it fetched to answer that question. Anthropic's security guide adds: "Tool call results from the connector that are part of stored chats are retained." In plain terms, the part Claude read stays with the conversation, in Anthropic's app, for as long as the conversation is kept.

How long that is depends on the plan. On Enterprise, Anthropic says chats are retained "indefinitely unless a custom retention period is set," and an Owner can set a period of 30 days or more. On a commercial plan, when a person deletes a conversation, Anthropic says it leaves their chat history immediately and is deleted from Anthropic's back-end systems within 30 days.

For a tax firm, this is the §7216 question from our Copilot vs Claude brief in a different shape. If return information is pulled into a chat, Anthropic processes and keeps it under Anthropic's terms, not Microsoft's. Anthropic documents a U.S.-only processing setting for its API, the service developers build on. It describes none for its Team and Enterprise plans. Claremont's position is the same as for Copilot: return information goes in only with each client's consent, and for Form 1040 clients the Social Security number stays out even with consent. Whether a particular disclosure needs consent is for your firm's counsel to decide. Put these facts in front of counsel before anyone connects a mailbox full of returns.

04

Where you can limit it

+

In Microsoft Entra. An administrator can withdraw the consent, in part or in full. The connector's two apps can require assignment, so only named users or groups can sign in to them. Anthropic's guide supports Conditional Access sign-in rules. It recommends a separate multifactor policy if your firm's existing one does not apply to the connector's sign-in.

In Claude. On Team and Enterprise, Owners turn the connector on and decide whether write actions are on. They can also limit which members use it, or switch off specific permissions. On Enterprise, except for public sector organizations, Anthropic's Compliance API lets your firm's IT pull activity feeds, chat data, file content and audit log events out of Claude.

The record. The connector's Microsoft Graph calls, its requests to Microsoft 365, "are logged in your organization's Microsoft 365 audit log," Anthropic says. Anthropic also logs sign-ins and each tool the connector runs, on its own side. Do not assume Purview's rules for Copilot, such as its data loss rules, cover the connector. Microsoft documents them for Microsoft 365 Copilot and Copilot Chat. Nothing in that documentation extends them to another vendor's app. Neither Anthropic's setup guide nor its security guide mentions sensitivity labels, the labels that mark confidential files.

Sources

§Sources17 sources · Anthropic 11 · Microsoft 6+

Claremont Security sets up governed Microsoft Copilot for regulated firms, including the decision on outside AI apps like this one: which people, which plan, read or write, and the record. To see where a firm's data can travel, try the AI Exposure Check. It is free and needs no account: claremontsecurity.com/ai-exposure