Guide

Guide to using Claude with Microsoft 365 while maintaining compliance

One route puts Anthropic's models inside Microsoft Copilot under Microsoft's contract. The other puts Anthropic's own product on your mailbox and files under Anthropic's. Which one is running is a question for the outsourcing register, and for whoever switched it on.

By Peter Philp  |  Last reviewed: 21 September 2026

 

On 18 September 2026 Microsoft revised its guidance on Anthropic models in Microsoft Online Services, eight days after its previous revision. The page now sets out three positions for those models: under Microsoft's contract, under Anthropic's with data retention, and, for the newest models, one or the other depending on an organisation's eligibility. That page governs the first of two arrangements by which Claude, Anthropic's AI assistant, reaches Microsoft 365. The second is Anthropic's own product, connected through a connector and a set of Office add-ins. Each has its own contract, control point and default state, and a supervised institution in Geneva or Dubai needs to know which one it is running.

The two look alike from a desk. In both, a member of staff types a question and Claude answers over the organisation's documents. Underneath, the party processing the data, the agreement that covers it and the administrator able to stop it are all different, and so is the outsourcing register entry each requires.

How the two arrangements compare

Claude models inside Microsoft Copilot Microsoft 365 connected to Claude
What the user opens
Microsoft Copilot, Researcher, Copilot Studio, Copilot in the Microsoft 365 apps Claude on web, desktop or mobile, plus add-ins in Word, Excel, PowerPoint and Outlook
What is in use
Anthropic models behind Microsoft's prompts, orchestration and retrieval Anthropic's product in full: projects, skills and its own connectors
Identity
Microsoft Entra ID Claude account; single sign-on on Team and Enterprise plans
Retrieval
Microsoft Graph, limited to content the user may already open Outlook, SharePoint, OneDrive and Teams under delegated permissions
Billing
Microsoft, inside the Copilot licence Anthropic, per seat
Governing contract
Microsoft Product Terms and Data Protection Addendum, Anthropic as subprocessor; separate opt-in for data-retention models Anthropic commercial terms and data processing addendum
Who switches it on
AI Administrator or Global Administrator, Microsoft 365 admin centre; Power Platform admin centre for Copilot Studio Entra Global Administrator consent, plus the Claude organisation owner on Team and Enterprise
Default state
On in most commercial cloud regions; off in the EU, EFTA and the UK Off until a Global Administrator consents; then read-only, write tools off until enabled

Claude models inside Microsoft Copilot

In the first arrangement Microsoft licenses Anthropic's models and serves them inside its own products: Microsoft Copilot, the Researcher agent, Power Platform, Copilot in the Microsoft 365 apps and Copilot Studio, Microsoft's tool for building agents. The user stays in Microsoft's interface, signs in with Microsoft Entra ID, the identity service behind every Microsoft 365 account, and, where the feature offers it, picks Claude or sees an indicator that a Claude model is in use.

Since 7 January 2026 Anthropic has been a Microsoft subprocessor, a supplier that handles data on Microsoft's behalf, working under Microsoft's Product Terms and Data Protection Addendum. The Customer Copyright Commitment, Microsoft's undertaking to defend clients against copyright claims over Copilot output, extends to Anthropic models in Microsoft Copilot and Copilot Studio. Microsoft lists its subprocessors in the Service Trust Portal, the reference an outsourcing entry should cite. Retrieval runs on Microsoft Graph, the layer that connects Copilot to mail, files and chats, so Copilot reaches only what the signed-in user may already open.

The two look alike from a desk. Underneath, the party processing the data, the agreement that covers it and the administrator able to stop it are all different.

One category sits outside that contract. Models Microsoft labels "Anthropic models with Data Retention" run under Anthropic's own commercial terms and data processing addendum, are off by default everywhere and need a separate opt-in. Under that arrangement Anthropic stores most inputs and outputs for up to 30 days, content flagged by its trust and safety classifiers for up to two years and classification scores for up to seven years, and does not use retained data for training without express permission. For its newest models the page adds an eligibility test: some organisations receive them as subprocessor models under Microsoft's terms, with no retention and no further opt-in, and others receive them only as data-retention models. Which side an organisation is on is a question for the Microsoft account team.

The default state depends on region.

  • Most commercial cloud tenants have Anthropic models on by default; a tenant is an organisation's own instance of Microsoft 365.
  • Tenants in the European Union, the European Free Trade Association, EFTA, which includes Switzerland, and the United Kingdom have them off by default, because the models are excluded from the EU Data Boundary, Microsoft's commitment to store and process EU and EFTA clients' data inside those regions, and from in-country processing commitments where those apply. A second setting, introduced on 3 April 2026, lets those tenants make Anthropic the default model for Copilot in the Microsoft 365 apps.
  • Non-federal organisations in the United States Government Community Cloud, GCC, gained a setting on 22 July 2026; federal organisations in that cloud, and everyone in GCC High, Department of Defense and other sovereign clouds, have no option at all.

For a Geneva institution the switch is off until someone turns it on. For a DIFC institution on commercial cloud it is on until someone turns it off. The control sits in the Microsoft 365 admin centre under Copilot, Settings, View all, then "AI providers operating as Microsoft subprocessors", where an administrator assigns access to named users or security groups.

Microsoft 365 connected to Claude

The second arrangement runs the other way. Anthropic's product reaches Outlook, SharePoint, OneDrive and Teams through the Microsoft 365 connector, and its Office add-ins put Claude inside Word, Excel and PowerPoint, with Outlook in beta. The connector is hosted by Anthropic, uses delegated permissions so Claude holds no access beyond the signed-in member's own, retrieves content on demand and caches no file content. It runs under Anthropic's commercial terms and data processing addendum, and Anthropic holds a SOC 2 Type 2 report and ISO 27001 certification of its own.

Three facts shape the control point.

  • The connector is available on every Claude plan, including the free one, to any Microsoft Entra work account once a Global Administrator has consented for the tenant. A member could therefore connect a corporate mailbox to a personal Claude account. Anthropic's answer is a Team and Enterprise setting that restricts verified-domain connectors to the organisation's own Claude workspace; Microsoft's is app assignment in Entra, limiting the two Claude applications to named groups.
  • Write tools, which send mail, manage calendar events, create files in OneDrive and SharePoint and post to Teams, are a separate decision, need an administrator to enable them, and Teams messaging has to be enabled tool by tool.
  • Conditional Access, the Entra policy engine that decides who may sign in from where, behaves differently here. In Anthropic's own testing, every request after the initial sign-in comes from Anthropic's servers, carrying the device recorded at connection time. Group and multi-factor policies work; device compliance is checked against the recorded device until the member reconnects; location, network and sign-in-frequency policies block the connector for everyone. A pilot should test this before a block is read as an outage.

Every call the connector makes to Microsoft Graph lands in the organisation's own Microsoft 365 audit log.

For a Geneva institution the switch is off until someone turns it on. For a DIFC institution on commercial cloud it is on until someone turns it off.

What each side costs

Claude inside Copilot needs a qualifying Microsoft 365 base licence and the Copilot add-on, and nothing from Anthropic. Copilot Studio agents meter separately on consumption, and that is the line finance should ask about after a pilot. The Anthropic side needs a paid Claude plan for the add-ins, and the Team or Enterprise plan for anything an organisation would want to govern: shared projects, single sign-on, central control of connectors, audit logging.

What the register entry should hold

The open question is whether anyone wrote down which one applies. For an institution supervised by the Swiss Financial Market Supervisory Authority, FINMA, the Dubai Financial Services Authority, the DFSA, or the Financial Services Regulatory Authority of ADGM, the FSRA, the useful output is an entry that states:

  • which arrangement is in use, and for which population
  • which setting was changed, by whom and when
  • whether models requiring data retention were permitted
  • whether connector write tools are on
  • what the Conditional Access test returned

Penta's own entry in that register reads ISO 27001:2022 certification and a SOC 2 Type 2 report.

For Penta clients, this is handled as part of your managed service and no action is needed. If you are not a client and cannot name who is closing these off, that is the gap we fill.

Questions people ask

Does Claude in Copilot use Anthropic's API or the Claude application?

The API, the programmatic route by which one piece of software calls another. Microsoft calls the models and wraps them in its own prompts, orchestration and retrieval, so none of the Claude application reaches the tenant.

Does anyone need a Claude account to use Claude in Copilot?

No. Access runs on Microsoft Entra ID and billing through the existing Microsoft agreement. A Claude account is needed only for the connector and the Office add-ins.

Is Claude already switched on in our tenant?

Probably, for a commercial tenant outside the EU, EFTA and the UK. Probably not inside those regions, where the setting defaults to no users. The answer sits in the Microsoft 365 admin centre under Copilot, Settings, View all, then "AI providers operating as Microsoft subprocessors".

Do Claude's own connectors and skills work inside Copilot?

No. Retrieval inside Copilot comes from Microsoft Graph and Copilot connectors. Anthropic's connectors and skills exist only within Anthropic's own product.

Can Claude write to Microsoft 365?

Through the connector, yes, once an administrator enables write tools; they ship off. Through Copilot, Claude acts within whatever permissions Copilot already has.

Can a team share work?

Yes, on either side, and never across both. Inside Microsoft that means published Copilot Studio agents and agents that draw on SharePoint content. Inside Claude it means shared projects, organisation-wide skills and administrator-controlled connectors on the Team or Enterprise plan. A team that wants one shared body of context has to decide which side holds it.

Does running Claude in Copilot make it a sovereign deployment?

No. Microsoft Copilot runs only in Microsoft's cloud and cannot run wholly on premises. The controls that apply are data residency commitments, the EU Data Boundary where it covers the workload, private network connections and Microsoft's data-governance controls. Anthropic models are currently excluded from the EU Data Boundary.

Which arrangement should an organisation choose?

Work backwards from the task. Drafting, summarising and analysis inside existing documents point to Copilot with Claude selected. Shared context, reusable skills and connections to systems outside Microsoft point to Anthropic's product with the Microsoft 365 connector attached.

References

  1. Microsoft Learn, "Anthropic models in Microsoft Online Services", updated 18 September 2026
  2. Microsoft Learn, "Understanding AI functionality and models in Microsoft Online Services", updated 10 September 2026
  3. Microsoft Learn, "Copilot in Microsoft 365 apps with Anthropic models"
  4. Microsoft Learn, "Allow external language models for generative responses", Power Platform, updated 28 May 2026
  5. Microsoft 365 Blog, "Expanding model choice in Microsoft 365 Copilot", 24 September 2025
  6. Claude Help Center, "Microsoft 365 connector security guide", updated September 2026
  7. Claude Help Center, "Set up the Microsoft 365 connector", updated September 2026
  8. Claude Help Center, "Use Claude for Outlook", September 2026
  9. Anthropic, "Claude for Microsoft 365", product page, 2026