Claude in Microsoft 365 — Native Copilot or MCP connector?

M365 security & compliance

36one.cloud / Fractional Architect Architecture note · 001 / May 1, 2026

v1.0 · M365 security & compliance

Claude in Microsoft 365. Built-in Copilot or MCP connector?

An architecture-side reading: why ISO/SOC 2 and the no-training commitment are not enough to call the two options equivalent.

AUTHOR Myriam Spitz Mooser Fractional Architect — Microsoft 365 & Azure AI
FOR IT & Risk decision-makers

Reading ~ 4 min · 9sections

Two architectures, not one conversation.

It's the same thing — Claude in both cases. The contracts are in place, the data isn't used for training, so the risk is the same.
— The shortcut to avoid
  • Two distinct architectures, two trust perimeters, two contractual regimes — and three material differences that change the audit profile.
  • 01 — Contractual scope
  • 02 — Data governance
  • 03 — Residency & flows

Same model. Two paths.

On Microsoft's side, Claude shows up inside Copilot. On Anthropic's side, the MCP connector shows up inside the tenant.

OPTION A · NATIVE

Claude in M365 Copilot

Anthropic appears in Copilot as an alternative to OpenAI, under Microsoft oversight.

  • → Anthropic as Microsoft subprocessor
  • → Existing M365 DPA applies
  • → Enterprise Data Protection covers everything
  • → No third-party app added to the tenant
LICENSE M365 Copilot
OPTION B · THIRD-PARTY

Claude MCP Connector

Claude reads the tenant via Graph API, under Anthropic oversight, separate contract.

  • → Direct contract with Anthropic
  • → Separate Anthropic DPA required
  • → 2 Entra ID apps installed
  • → Delegated permissions via Graph API
LICENSE Any Claude plan

Who answers in case of incident?

The legal substrate changes with each option. Invisible in use, structuring in audit.

COPILOT

Single point of contact

Microsoft carries the relationship.

  • → M365 DPA, Customer Copyright Commitment, Microsoft breach notification.
  • → One vendor to audit.
SCOPE Microsoft
MCP CONNECTOR

Shared responsibility

Two parallel contracts.

  • → New Anthropic DPA to sign, separate breach notification.
  • → Different jurisdictions and retention periods.
SCOPE MS + Anthropic

Your Purview tools: how far?

On the Graph path, DLP applies on both sides. On the Claude conversation itself, additional Purview products are needed.

CAPABILITYCOPILOTMCP CONNECTOR
Sensitivity labels in the conversation Preserved Label lost
Purview DLP on Graph extraction Native Inherited
DLP on Claude prompt / response DSPM for AI MDCA / Network DSec (E5)
Purview audit logs (Graph API) Complete Tool calls logged
eDiscovery on AI conversation Included Not included
MFA & Conditional Access (Entra) Honored Honored

Where does the data live after reading?

Both options leave the EU Data Boundary. The contractual scope of each flow differs.

OPTION A · COPILOT

M365 tenant → Azure (EDP) → Anthropic (US)

Outside EU Data Boundary. Off by default in EU/UK.

  • → Microsoft contractual coverage across the chain.
OPTION B · MCP CONNECTOR

M365 tenant → Graph API → Anthropic infra (US)

Outside EU Data Boundary. Datacenters primarily US.

  • → Anthropic contractual coverage from the Graph onward.

On one page.

Eleven criteria, two columns. The full grid, no interpretation.

CRITERIONM365 COPILOTMCP CONNECTOR
Contractual framework Microsoft DPA + EDP Direct Anthropic DPA
Customer Copyright Commitment Covered Not applicable
EU Data Boundary Outside EU DB · off by default Outside EU DB · US
Model training No (EDP) No (if data sharing off)
Sensitivity labels tracked Preserved Lost on Claude side
Purview DLP · Graph extraction Native Inherited (delegated permissions)
DLP on AI prompts / responses DSPM for AI MDCA / Network DSec (E5)
Audit logs (Graph API) Complete Logged via Purview
eDiscovery on AI conversation Included Not included
Third-party Entra apps None 2 apps installed
License M365 Copilot · $30/user/month Any Claude plan

What actually changes.

Sources & references.

Official documentation and independent analyses consulted for this note.

— OFFICIAL DOCUMENTATION

— INDEPENDENT ANALYSES