Compliance FAQ

Claude Microsoft 365 connector compliance FAQ

This page answers the short review questions administrators, security reviewers, and approvers usually ask about access, data handling, logging, revocation, and plan availability.

FAQ

Access and identity

These questions cover who can sign in, what delegated permissions mean, and how tenant-backed identity changes rollout planning.

What does delegated access mean for this connector?+

Microsoft says delegated access means the app acts on behalf of the signed-in user, and Anthropic says the connector uses delegated permissions for Microsoft 365 access. The connector cannot exceed the combination of the granted scopes and the user’s own access to data.

Can users access data they do not already have permission to view?+

Anthropic says users can only access Microsoft 365 data they already have permission to see. The security guide also says users cannot bypass SharePoint sharing settings or access other users’ private files or emails.

Do personal Microsoft accounts work with the connector?+

No. Anthropic says the connector requires a Microsoft 365 account tied to a Microsoft Entra tenant and that personal Microsoft accounts such as Outlook.com or Hotmail cannot be used to authenticate.

FAQ

Data handling

These questions cover what stays in Microsoft 365, what Anthropic says about content handling, and what read-only access does not allow.

Does the connector write back into Microsoft 365?+

No. Anthropic documents the current connector as read-only and says it cannot send emails, schedule meetings, create or modify documents, or post Teams messages.

Does Anthropic cache file content or store Microsoft passwords in the connector layer?+

Anthropic says the connector operates as a secure proxy, retrieves content on demand during active queries, and does not cache file content. The security guide also says the MCP server does not store or manage Microsoft credentials.

Do conditional access and DLP controls still apply?+

Yes. Anthropic says the connector supports existing Entra policies such as MFA, device compliance, IP restrictions, and group-based access, and that delegated permissions respect Microsoft 365 DLP policies.

FAQ

Logging and audit

These questions cover where to look for evidence, what roles are needed, and how long reviewers may wait before logs appear.

Where should reviewers look for usage evidence?+

Anthropic says all Graph API calls made by the connector are logged in your organization’s Microsoft 365 audit log and that Anthropic also logs authentication and tool execution events.

What roles are needed to search the Microsoft 365 audit log?+

Microsoft says people searching the audit log need the Audit Logs or View-Only Audit Logs role in Microsoft Purview. Exchange admin tooling can also be required for cmdlet-based search workflows.

How quickly should audit records appear?+

Microsoft says audit records for core services such as Exchange, SharePoint, OneDrive, and Teams are typically available after 60 to 90 minutes, but Microsoft does not guarantee a specific time after the event occurs.

FAQ

Revocation and change management

These questions cover how to shut down the connector, how to narrow scope, and how to control the first pilot group.

How can we revoke access quickly if the pilot needs to stop?+

Anthropic documents several revocation paths: individual users can disconnect the connector, Team and Enterprise owners can disable it for the organization, and Microsoft Entra admins can revoke specific scopes or all tenant access.

Can we disable only one Microsoft 365 surface instead of shutting everything off?+

Yes. Anthropic says you can revoke specific capabilities in Microsoft Entra. Their examples include revoking Sites.Read.All for SharePoint, Mail.Read for Outlook, Chat.Read for Teams chat, and Files.Read or Files.Read.All for OneDrive file access.

Can we run a small pilot group before broad rollout?+

Yes. Anthropic recommends using Microsoft Entra enterprise app assignment to restrict the connector to specific users or groups, then expanding the pilot progressively.

FAQ

Plan and availability notes

These questions cover the current public wording about plan access and the extra organization gating Anthropic documents for Team and Enterprise.

Is the connector available on all Claude plans?+

Not from one page alone. On April 11, 2026, Anthropic's docs page said Team and Enterprise plan users only, while the enable guide and security guide both said the connector was available on all Claude plans. Verify the current wording before publishing internal guidance.

Do Team and Enterprise tenants still require organization-owner enablement?+

Yes on Team and Enterprise. Anthropic says organization owners must enable the connector in Claude before team members can connect, and a Microsoft Entra Global Administrator must still complete the one-time consent process for the tenant.

What does read-only mean in practice for this connector?+

Anthropic says read-only means the connector cannot send email, schedule meetings, create or modify documents, or post Teams messages. Anthropic also says user-level access is supported, while service-principal authentication is not.

Official Sources

Use the official references below when you publish or review internal guidance.

Keep the April 11, 2026 plan-availability mismatch visible until Anthropic's public pages are aligned again.