- If your organization runs Claude Desktop on third-party inference, see Connect to Microsoft 365 instead
- If you’re in a US government deployment, see Set up the Microsoft 365 connector in the government section
Review what Claude can do
All access is delegated: Claude acts on your behalf and can read or change only what your Microsoft 365 account can already read or change. The table lists what Claude can do in each service; the write column applies only when your administrators have turned on write actions.Set up the connector
What you do first depends on your Claude plan:- Free, Pro, and Max: there’s no organization-level step in Claude. Skip to Connect your account. A Microsoft Entra Global Administrator still needs to grant tenant consent for your Microsoft organization
- Team and Enterprise: a Claude Owner or Primary Owner adds the connector for the organization first, and then each member connects their account
Prerequisites
Check these before you start:- A work or school Microsoft account on a Microsoft Entra tenant. Personal accounts such as outlook.com, hotmail.com, or live.com aren’t supported
- Global Administrator access to the Microsoft Entra tenant
- On Team and Enterprise plans: the Owner or Primary Owner role in Claude, and active Microsoft 365 accounts for all users
Add the connector for your organization
On Team and Enterprise plans, an Owner or Primary Owner adds the connector once for everyone. The steps below are the automatic setup, which is the recommended path.1
Open organization connectors
In claude.ai, go to Organization settings > Connectors.
2
Add Microsoft 365
Select Add, then All available. Find Microsoft 365 and select Add to your team.
3
Connect and grant consent
Connect your own account and grant the organization-wide permissions.
4
Adjust access if needed
Restrict which users can use the connector, or revoke specific permission scopes.
Connect your account
Once the connector is available to you, connect your own Microsoft 365 account.1
Open your connectors
Go to Customize > Connectors in claude.ai. Customize is the page that holds your connectors, skills, and plugins.
2
Connect Microsoft 365
Find Microsoft 365 and select Connect.
3
Sign in to Microsoft
Sign in with your work or school Microsoft credentials.
Try the connector
In a conversation, select + at the lower left of the message box, select Connectors, and turn on Microsoft 365. Then ask a question that needs Microsoft 365 data, or ask Claude to take an action such as sending an email or updating a file. Claude detects which tools it needs and uses them. For example, ask Claude:- Find the Q4 strategic planning document in SharePoint
- Summarize email conversations about the product launch
- What discussions happened in Teams about the marketing campaign?
- Draft a reply to the latest email about the vendor contract
- Schedule a 30-minute sync with the design team next week
Write actions
Claude can take actions in Outlook, SharePoint, and Teams, as listed in the write column of Review what Claude can do. Read and search tools work the same whether or not write actions are enabled. Claude can’t attach files to the drafts it creates. Your organization’s administrators control write actions in two places: the connector’s permissions in Microsoft Entra, and the Microsoft 365 connector configuration under Organization settings > Connectors.Approve the write permissions
If your tenant approved the connector before a write permission (mail, calendar, mailbox settings, file writes, or Teams messages) was added, a Microsoft Entra Global Administrator or Application Administrator approves the added permissions once for the tenant. Reconnecting doesn’t add them. See Approve permissions added to the connector.Turn on write actions
If write actions are off for your organization, administrators turn them on for all users in the Microsoft 365 connector configuration, or enable them for specific users with role-based access control (beta). Administrators also check the restriction on each tool that sends Teams messages. A per-tool restriction overrides the Default restriction row, so a tool that is blocked for all users stays unavailable until an administrator changes its restriction. To let users choose those tools:1
Open the connector's configuration
Open the Microsoft 365 connector under Organization settings > Connectors.
2
Find Tool permission restrictions
Find Tool permission restrictions.
3
Allow each Teams messaging tool
Set each Teams messaging tool so that users can choose it.
Permissions
All permissions are delegated: Claude acts on behalf of users and can only access and change content that you already have permission to access and change in Microsoft 365. Write actions are available when your administrators enable them, as described in Write actions.Approve permissions added to the connector
If your tenant approved the connector before Anthropic added a permission to it, the Claude feature that needs the permission fails with a permission error until a Microsoft Entra administrator approves it. For example, listing your teams fails until your tenant approvesTeam.ReadBasic.All. Disconnecting and reconnecting the connector in claude.ai doesn’t add the permission, because Microsoft doesn’t show a consent screen again once the tenant has approved the connector. The connector’s Permissions page in the Entra admin center (under Enterprise applications, listed as M365 MCP Server for Claude) shows only the permissions your tenant has already approved, so a missing permission doesn’t appear there.
A Global Administrator or Application Administrator approves the added permissions for the whole tenant by opening the admin consent link and accepting the list it shows.
1
Open the admin consent link
Replace
YOUR_TENANT_ID with the Directory (tenant) ID shown in Entra admin center > Overview, then open the link. The client_id value is the connector’s Application ID, shown on the M365 MCP Server for Claude enterprise application’s Overview page.2
Review the permissions and accept
The consent screen lists every permission the connector requests, including any added since your tenant first approved it and the permissions that write actions need. The Teams tools use
Team.ReadBasic.All to list teams, People.Read to look up people, and ChatMessage.Send, ChannelMessage.Send, and Chat.Create to send messages. Select Accept.3
Confirm the approval
Check the address bar of the page Microsoft sends you to. The approval succeeded when the address contains
admin_consent=True, and the approved permissions then appear on the connector’s Permissions page.Troubleshooting
If something isn’t working, start with the case that matches what you see.Authentication failures
Authentication failures
If sign-in fails, work through these checks:
- Confirm you’re signing in with your work or school Microsoft 365 credentials, not a personal account
- Check that your Microsoft 365 license is active
- Review your organization’s third-party app policies
- Try a different browser, or clear cookies and cache and sign in again
Documents not found
Documents not found
If Claude can’t find a document you know exists:
- Confirm you can open the document directly in Microsoft 365
- Make sure the document is stored in SharePoint or OneDrive, not only on your computer
- Wait and retry for recently uploaded documents, which can take time to index
- Name the specific SharePoint site, or search by the exact filename
Incomplete search results
Incomplete search results
If results are partial or miss what you expected:
- Be more specific about what you need
- Specify locations and date ranges
- Use exact phrases from the content
- Break a complex request into simpler questions
Next steps
- Get started with connectors: set up another connector and use it in conversations
- Connectors directory: browse verified and community integrations