Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Connecting Claude to Microsoft 365 the Right Way

Most of the businesses we talk to have moved past the question of whether their people will use AI. They already are. The real question is whether that use is connected to company data in a controlled way, or whether it is happening quietly through personal accounts that no one in IT can see.

Claude now connects directly to Microsoft 365. Done properly, that is genuinely useful. Done casually, it is an unmanaged pathway between your SharePoint, email and Teams content and an account your business does not control. The difference between the two comes down to a handful of decisions, and they are worth making deliberately.

Start With the Plan, Not the Connector

This is the decision that matters most, and it is made before anyone touches a setting.

Consumer plans (Free, Pro and Max) operate under consumer terms. Those terms permit data to be used for model training where the user consents, with retention extending to five years for users who have opted in. That is an entirely reasonable arrangement for someone using AI for personal projects. It is not an arrangement you want sitting underneath your client contracts, your financials or your staff records.

Claude Teams is the minimum commercial floor for business use. Teams and Enterprise remove training on your data altogether and, just as importantly, introduce the administrative oversight that consumer tiers simply do not have. If your people are going to use Claude with company information, the licence needs to come from the company.

Check What Is Already Connected to Your Tenant

Before planning a rollout, it is worth finding out what is already there.

If your Entra ID tenant allows users to consent to applications themselves, an individual staff member can authorise the Claude connector against their own account without IT ever seeing it. Nothing is broken and no policy alarm sounds. The connection simply exists.

The check takes a few minutes. In Microsoft Entra, look through Enterprise Applications for entries containing "Claude" or "MCP". Anything you find is an existing connection between an AI account and your tenant. It is also worth knowing that paid personal plans allow Office extensions to run inside Excel without an executable being installed, which means they slip past the software controls most businesses rely on.

None of this means anything has gone wrong. It means the visibility is missing, and visibility is the thing worth fixing first.

Connecting It Properly Is a Two-Person Job

A correctly configured connection requires two separate approvals, deliberately.

  • In Claude: An Owner account goes to Organization Settings, then Connectors, and adds Microsoft 365 to the organisation.
  • In Microsoft: A Global Administrator grants tenant-wide consent through Microsoft's permission screen.

The important detail sits underneath that second step. The connector uses delegated permissions, which means it operates as the signed-in user and respects the access controls already in place. Claude cannot see what the user cannot see, and it cannot bypass your existing permission structure.

That is reassuring, but it carries a catch worth naming. Your permissions model is now doing real work. If a SharePoint site has been shared more widely than anyone intended, or an old team still has members who left the department two years ago, AI makes that content far easier to surface than it used to be. A permissions review before switching the connector on is time well spent, and it is usually the step that gets skipped.

Governance Does Not Stop at Consent

Granting consent is not an all-or-nothing switch. Once the connector is in place, administrators get granular control over what it can actually do. Individual capabilities such as SharePoint search or Teams chat access can be left blocked by default, restricted, or approved case by case as the business finds genuine uses for them.

The sensible pattern is to start narrow and open up deliberately, rather than enabling everything on day one and working out afterwards what people are doing with it.

A Note on Data Residency

One caveat deserves attention from any business with strict residency obligations. Where Anthropic operates as a Microsoft subprocessor within Copilot, data can move outside Azure, primarily to United States-based AWS or GCP infrastructure.

If your organisation carries firm GDPR or data residency requirements, the appropriate move is to disable Anthropic in the admin centre until you have satisfied yourself on those questions, rather than assuming the Microsoft wrapper keeps everything inside Azure.

What All IT Is Doing About This

We are rolling out Claude Teams and Enterprise for clients, set up properly rather than switched on and hoped for. In practice that means:

  • Licensing sits with the business rather than with individuals.
  • Tenant consent is granted once by an administrator instead of repeatedly by staff.
  • Permissions are reviewed before the connector is enabled.
  • Connector capabilities are opened up deliberately as real uses emerge.
  • There is a named owner inside the business who can see what is connected and who is using it.

We are also using Claude heavily inside our own operations, which means the guidance we give clients comes from having done the work ourselves rather than from a vendor datasheet. We are happy to share what has worked and what has not.

Where to Start

If you are not sure what is already connected to your tenant, that is the first thing to find out. Speak to your Relationship Manager and we will run the check with you, walk through what we find, and set out what a properly governed rollout would look like for your business.

"The businesses that get value from AI over the next couple of years will be the ones that gave their people a sanctioned way to use it. The alternative is not that staff stop using AI. It is that they keep using it somewhere you cannot see."

Source This article draws on Connecting Claude Securely to Microsoft 365 by T Minus 365, which is worth reading in full if you want the technical detail behind these recommendations.
Tom Buckley Founder & Managing Director, All IT Services Tom has supported Australian businesses with managed IT, cyber security and AI since 2005. He works with hospitality groups, not-for-profits, financial services firms and SMBs across Sydney, Melbourne, Brisbane and the Central West NSW, specialising in IT strategy, Microsoft 365, Essential 8 and SMB1001 cyber security, and practical AI for business.

Meet the team  |  LinkedIn  |  Talk to Tom

Frequently Asked Questions

Yes. Claude Teams is the minimum commercial tier for business use. Consumer plans (Free, Pro and Max) allow data to be used for model training and do not include the administrative oversight businesses need. If staff are going to use Claude with company data, the licence needs to come from the company, not from individual personal accounts.
In Microsoft Entra, check Enterprise Applications for any entries containing "Claude" or "MCP". If your tenant allows users to consent to applications themselves, a staff member may have already authorised the connector without IT being notified. The check takes a few minutes and is worth doing before planning any rollout.
No. The connector uses delegated permissions, which means it operates as the signed-in user and respects your existing access controls. Claude cannot see what the user cannot see. However, if SharePoint sites or Teams have been shared more broadly than intended, AI makes that content easier to surface, which is why a permissions review before enabling the connector is strongly recommended.
Personal plan terms permit data to be used for model training, with retention extending to five years for users who have opted in. More importantly, IT has no visibility or control over a connection made through a personal account. The risk is not that something is broken. It is that the visibility is missing, and you cannot manage what you cannot see.

Not Sure What's Already Connected to Your Tenant?

We'll run the check with you, walk through what we find, and map out a properly governed AI rollout for your business.


Posted in Uncategorized