
Claude AI M365 Connector: What Manchester Businesses Must Know Before Granting Access
Artificial intelligence is moving fast, and so is the way AI tools connect to your business systems. One integration attracting growing interest — and generating some genuine concern from security-conscious IT teams — is the Claude AI Microsoft 365 MCP connector.
If someone in your organisation is asking about connecting Claude AI to your Outlook, Teams, or SharePoint environment, this guide explains exactly what that means, what it can access, and what you need to have in place before you say yes.
This Is Not an Outlook Add-In
The first thing to understand is that the Claude AI M365 connector is not a simple Outlook plug-in. It is an Entra ID Enterprise Application — a cloud-to-cloud integration registered directly in your Microsoft Azure/Entra ID tenant.
That distinction matters enormously. An Outlook add-in only sees the email you currently have open. An Entra ID Enterprise Application, once consented to, can access data across your entire Microsoft 365 environment — every inbox, every calendar, every Teams message, every SharePoint file — based on the Microsoft Graph API permissions it has been granted.
This is the same architecture used by enterprise SaaS tools like Salesforce, DocuSign, and Zoom when they integrate with Microsoft 365. It is powerful and legitimate when properly managed. The risk arises when businesses do not understand what they have consented to.
How It Works: MCP and Microsoft Graph API
The connector uses the Model Context Protocol (MCP) — an open standard developed by Anthropic — to bridge Claude AI with your Microsoft 365 data. Think of MCP as a standardised interface that tells Claude what data sources are available and how to query them.
The data flow looks like this:
- A user or administrator grants the Claude AI Enterprise Application consent in Entra ID
- The application receives an OAuth 2.0 token scoped to the permissions it was granted
- When Claude is asked to help with an email task, it queries the Microsoft Graph API using that token
- Graph API returns live data from your Microsoft 365 tenant — full thread, attachments, calendar, contacts, Teams messages
- That data is processed by Claude on Anthropic’s infrastructure and the response is returned
The critical word above is live. Claude is not processing a snippet of text that someone has copied in. It is making authenticated API calls to your Microsoft 365 environment and pulling real data in real time.
What Permissions It May Request
When an Entra ID Enterprise Application is registered, it requests specific Microsoft Graph API permission scopes. Depending on the connector’s configuration, these can include:
- Mail.Read / Mail.ReadWrite — full read access to every email in the authorised mailbox, every folder, every attachment
- Calendars.Read / Calendars.ReadWrite — all calendar events, attendee lists, meeting content, and private appointments
- Contacts.Read — every contact in the address book including names, numbers, emails, and notes
- Files.Read / Files.ReadWrite — OneDrive files, shared documents, and linked content
- Chat.Read / ChannelMessage.Read — private Teams chats and channel messages
- Sites.Read — SharePoint document libraries accessible to the user
If an administrator grants tenant-wide admin consent rather than per-user consent, these permissions apply to every user in the organisation — not just the individual who installed the connector. A single consent click can grant Claude AI read access to your entire company’s data.
Important: Unlike an Outlook add-in — which stops working when you close Outlook — an Entra ID Enterprise Application maintains persistent OAuth tokens. Claude’s access to your M365 data continues in the background even when no one is actively using it.
The Account Tier Problem
How Anthropic handles the data it receives depends entirely on which Claude account type is used when the connector is authorised. This is the detail that most businesses miss.
- Free and Pro personal accounts (claude.ai) — conversations and processed data may be used to help improve Anthropic’s AI models. The free account has this enabled by default.
- Claude for Work — data is not used for model training by default, and organisational admin controls are available.
- Claude Enterprise — data is never used for training, with full admin controls and audit capability.
If a member of staff — or an IT administrator — connects the M365 MCP connector using a personal Claude Pro account, everything Claude accesses via the Microsoft Graph API could be used to improve Anthropic’s models. Your client correspondence, your HR discussions, your financial emails, your Teams conversations: all processed through a personal account with no organisational controls and no ability to request deletion.
UK GDPR Obligations
Your organisation is the data controller for the personal data stored in your Microsoft 365 environment. When an Entra ID Enterprise Application grants an AI system access to that data, you carry full GDPR responsibility for what happens to it.
Unless you have:
- A formal data processing agreement (DPA) with Anthropic
- A business-tier Claude account (Claude for Work or Claude Enterprise)
- Completed a Data Protection Impact Assessment (DPIA) under Article 35
- Reviewed and minimised the Graph API permissions granted
…then connecting your Microsoft 365 tenant to Claude AI via the MCP connector is almost certainly non-compliant with UK GDPR. The ICO’s enforcement focus on AI-related data processing is growing, and unmanaged AI connectors with tenant-wide access represent exactly the kind of scenario they are scrutinising.
Fines for serious infringements can reach £17.5 million or 4% of global annual turnover — whichever is higher.
What to Do Before Granting Access
If someone in your organisation is requesting this integration — or if you suspect it may already be active — here are the immediate steps:
1. Audit Your Entra ID Enterprise Applications
Go to the Microsoft Entra admin centre (entra.microsoft.com), navigate to Enterprise Applications, and review what is registered in your tenant. Look for any Claude AI or MCP-related applications and check the permissions that have been consented to.
2. Restrict User Consent Policies
By default in many Entra ID configurations, standard users can consent to applications requesting permissions marked as “low risk.” This is a dangerous default. Set your user consent policy to require admin approval for all third-party application consent requests.
3. Check for Existing Admin Consent Grants
In the Entra admin centre under Enterprise Applications > Permissions, review any existing admin consent grants. Revoke any you did not deliberately authorise.
4. Establish an AI Tool Policy
Before any AI-to-M365 integration goes live, you need a written policy that defines: which AI tools are approved, what account tier is required, what Graph API permissions are acceptable, and who has authority to authorise new integrations.
5. Use Only Business-Tier Claude Accounts
If you proceed with the integration, it must be authorised using a Claude for Work or Claude Enterprise account. Personal accounts — even paid Pro accounts — must never be used to authorise access to company data.
6. Apply Least Privilege to Graph API Permissions
Request only the permissions actually needed. Read-only where possible. Avoid tenant-wide application permissions unless there is a specific, documented business requirement.
How Pro Business Can Help
We work with businesses across Manchester and the North West to navigate exactly these decisions: emerging AI tools that offer genuine productivity value, but need to be deployed correctly to stay safe and compliant.
Our AI and M365 security services include:
- Entra ID Enterprise Application audit — reviewing all registered applications and consent grants in your tenant to identify any unauthorised or high-risk AI connectors
- Graph API permission review and remediation — assessing what your M365 data is exposed to and recommending the minimum necessary permissions
- AI usage policy development — clear, enforceable policies for which AI tools staff can use, with what data, and under what conditions
- DPIA support — completing the Data Protection Impact Assessments required under UK GDPR before AI tools process personal data
- User consent controls — implementing Entra ID policies to prevent staff from independently granting third-party apps access to company data
- Staff training — ensuring your team — including IT administrators — understands what granting Enterprise Application consent actually means
The question is not whether AI tools like Claude belong in your business. Many of them are genuinely useful. The question is whether the integration has been done properly — with the right account tier, the right permissions, the right agreements, and the right controls.
If you are not sure, let us check. Contact the Pro Business team for a no-obligation Entra ID and AI connector audit.
Frequently Asked Questions
What is the Claude AI M365 MCP connector?
It is a cloud-to-cloud integration that connects Claude AI (made by Anthropic) to your Microsoft 365 environment via an Entra ID Enterprise Application. It uses the Model Context Protocol (MCP) and Microsoft Graph API to give Claude access to your emails, calendars, files, and Teams messages in real time. It is not an Outlook add-in — it is a tenant-level integration with persistent access.
Can my staff install this without IT knowing?
Potentially, yes — depending on your Entra ID user consent settings. If your tenant allows users to consent to low-privilege application permissions, a staff member could authorise the connector using their own Claude account without IT or admin approval. This is why reviewing and restricting your user consent policy is one of the first recommended steps.
Is it GDPR-compliant to use this connector?
Not without the right setup. You need a formal data processing agreement with Anthropic, a Claude for Work or Enterprise account (not a personal account), a completed DPIA, and properly scoped Graph API permissions. Using a personal Claude account to authorise M365 access is almost certainly non-compliant with UK GDPR.
What is the difference between a personal Claude account and Claude for Work?
Personal Claude accounts (Free and Pro on claude.ai) may use conversation data to improve Anthropic’s AI models, offer limited data retention controls, and provide no admin oversight. Claude for Work and Claude Enterprise do not use data for training by default, offer organisational admin controls, and support proper data governance — making them the only acceptable account types for business use.
How do I check whether the connector is already active in my tenant?
Log in to the Microsoft Entra admin centre (entra.microsoft.com), navigate to Enterprise Applications, and search for Claude or Anthropic. Review the permissions tab of any results to see what Graph API scopes have been consented to. Pro Business can carry out this audit for you as part of an Entra ID security review.
Does this connector keep working when staff are not actively using it?
Yes. Unlike an Outlook add-in that only operates when open, an Entra ID Enterprise Application holds persistent OAuth tokens. Unless access is explicitly revoked in Entra ID, the connector retains the ability to query your Microsoft 365 data continuously — even when no one is logged into Claude.
Can Pro Business help us deploy this safely if we want to use it?
Yes. We can help you assess whether the integration is right for your business, select the appropriate Claude account tier, configure the minimum necessary Graph API permissions, complete a DPIA, and implement Entra ID controls to manage ongoing access. Contact our team to discuss a compliant deployment.