Skip to main content

Claude Across the Microsoft Ecosystem

Claude became selectable across three Microsoft surfaces at GA: the model picker inside Microsoft 365 Copilot and Copilot Cowork, the agent authoring surface of Copilot Studio, and Microsoft Foundry, where the Messages API, prompt caching, extended thinking and tool streaming are all available. The Foundry Agent Service can use Claude as the reasoning core.

That availability is qualified by one fact most implementations discover late. Claude was enabled by default in most commercial tenancies from 2026-01-07, but remains disabled by default in EU, EFTA, UK, government and sovereign tenancies. Somebody in the organisation has to make and document that decision before the first model call reaches production.

Anthropic operates as a Microsoft subprocessor under Microsoft’s Product Terms and DPA, which is the contract covering the call. The enablement decision, once made, is defensible because that contract exists.

Where Inference Actually Happens

Anthropic offers no native EU data residency. For a European organisation that requires EU-only inference, the path runs through one of three hosting surfaces: Microsoft Foundry, AWS Bedrock in Frankfurt, Ireland or Paris, or Google Vertex AI. Each carries its own processing agreement and its own evaluation of which clause in the data protection record it satisfies.

A Data Processing Agreement is available for Anthropic Enterprise and API customers, and Standard Contractual Clauses cover EU-to-US transfers under the API. Knowing this before architecture decisions are made determines which surface inference runs on, which contract is in scope, and whether a later audit finds the residency claim credible or improvised.

Selecting Microsoft Foundry as the inference surface ties Claude calls to the same Microsoft DPA structure already in scope for the tenant, which simplifies the answer considerably.

The Audit Record

Claude Team and Claude Enterprise both exclude prompts from model training by default. No toggle sets this: commercial plans carry the exclusion without configuration, and it cannot be changed from the seat side.

The two plans differ where an enterprise governance function cares most. Claude Team, at $20 to $100 per seat per month, includes SSO, domain capture, admin controls, enterprise search and Claude Code on every seat. It carries no audit logs and no SCIM. Claude Enterprise, at $20 per seat plus API-rate usage, adds SSO with SCIM, audit logs, a Compliance API with programmatic access to activity logs, chats, files and projects, OpenTelemetry, an Analytics API, custom data retention and customer-managed encryption keys.

The absence of audit logs on Team is usually what decides between the two for organisations that report to a data protection function.

3 surfaces
Claude selectable at GA: Microsoft 365 Copilot, Copilot Studio, Microsoft Foundry
2026-01-07
commercial tenancies enabled by default: EU, EFTA, UK, government and sovereign remain off
$20 / seat
Claude Enterprise base rate: SSO, SCIM, audit logs, Compliance API, customer-managed keys
3 routes
EU-only inference: Microsoft Foundry, AWS Bedrock (Frankfurt, Ireland, Paris), Google Vertex AI

From Disabled by Default to a Decision an Auditor Can Read

Activation 3 steps
01

The Default Is Off in Your Tenancy

Claude became available by default across most commercial Microsoft tenancies from 2026-01-07. That default does not apply in EU, EFTA, UK, government or sovereign tenancies, where Claude is disabled at the platform level until a tenant administrator explicitly enables it. The decision to enable it is not a configuration task: it requires establishing which surfaces it will run on, under which contract, and against which data protection record the choice can be justified. Making that decision after the first production use is always worse than making it before: the audit trail starts the moment the model call is made, not the moment someone thought to document the choice.
02

The Contract the Call Runs Under

Anthropic operates as a Microsoft subprocessor under Microsoft's Product Terms and Data Processing Agreement. That covers Claude calls running through Microsoft surfaces: Microsoft 365 Copilot, Copilot Studio and Microsoft Foundry. It means the contractual framework already in place for the tenant's Microsoft workloads also covers Claude when it runs within those surfaces, and the organisation's DPA record does not need a new Anthropic-specific clause to cover that path. Calls to the Anthropic API directly are covered by Anthropic's own DPA, available for Enterprise and API customers, with Standard Contractual Clauses for EU-to-US transfers.
03

Three Surfaces, One Governance Decision Each

Microsoft 365 Copilot carries Claude Opus 4.8 and Claude Sonnet 4.6 in the model picker, selectable inside Copilot Cowork at GA from 2026-06-16. Copilot Studio allows Claude to run as the backing model for an agent built in the low-code authoring surface. Microsoft Foundry exposes Claude through the Messages API with prompt caching, extended thinking and tool streaming all available at GA, and the Foundry Agent Service can use Claude as the reasoning core. These are distinct surfaces with distinct governance paths: enabling Claude in Copilot Cowork does not automatically apply to Copilot Studio or to a Foundry-hosted agent, and each surface has its own admin control.
Identity & Residency 2 steps
04

Identity at Every Layer

Each Claude call in production has an identity question attached: which principal authorised the call, which credential is in the request header, and what that credential's lifecycle looks like. For Copilot surfaces the answer follows from the tenant's Entra ID configuration, since Microsoft handles the identity plane and the call is made under the user's Copilot seat. For direct Foundry or API calls, the application identity and its associated permissions have to be defined explicitly. Claude Enterprise adds SSO with SCIM for seat management, which keeps the identity plane consistent between the Microsoft workloads and the Claude-specific audit surface and removes a manual provisioning step as the rollout scales.
05

Where Inference Actually Happens

Anthropic has no native EU data residency. For a European organisation that requires EU-bound inference, three paths exist: Microsoft Foundry, which keeps the call inside the Microsoft infrastructure already governing the tenant; AWS Bedrock with Claude deployed in Frankfurt, Ireland or Paris; or Google Vertex AI. Each carries its own subprocessor agreement and requires a separate assessment of whether it satisfies the clause in the data protection record naming the inference location. The choice is made once, at architecture time, and any later change in residency position requires reassessing every workload that assumed the original choice. Running EU-only inference through Microsoft Foundry simplifies the answer because it reuses the DPA already in scope.
Data & Retention 2 steps
06

Model Training Is Off by Default, Without Configuration

Commercial plans, including Claude Team, Claude Enterprise and direct API access, exclude prompts from model training by default. This is not a setting the seat holder or the admin needs to turn on: it is the default position of the plan itself, and it cannot be changed from the seat or the tenant side. A security questionnaire asking whether user inputs are used to train the model has a one-sentence answer for any commercial plan, and that answer does not depend on verifying a per-user preference. A data protection impact assessment recording the training position does not need to caveat an opt-out mechanism, because none exists and none is required.
07

Retention, Keys and the Data Record

Claude Enterprise allows organisations to set custom data retention periods, so prompt and response history does not stay in Anthropic's systems longer than the organisation's own data lifecycle policy permits. Customer-managed encryption keys are available, which means the organisation holds the key material rather than Anthropic. These two controls together close the questions a data protection officer typically raises about inference data: how long it is retained, by whom, and under whose key. Neither control is available on Claude Team. If a data protection impact assessment names either one as a requirement, that decision effectively selects Claude Enterprise over Team before the seat price is discussed.
Rollout & Audit 2 steps
08

The Seat Model and What It Decides

Claude Team costs $20 to $100 per seat per month. It includes SSO, domain capture, admin controls, enterprise search and Claude Code on every seat. There are no audit logs and no SCIM provisioning. Claude Enterprise costs $20 per seat per month plus API-rate usage. It adds SCIM, audit logs, a Compliance API with programmatic access to activity logs, chats, files and projects, OpenTelemetry and an Analytics API, alongside custom retention and customer-managed keys. Claude Code ships on both plans. The absence of audit logs on Team is the single criterion that most commonly decides the plan tier for an organisation with a governance or compliance function: everything else on the list is preferable but negotiable.
09

What an Audit Can Be Shown

Claude Enterprise's Compliance API provides programmatic access to activity logs, chats, files and projects. That means an audit or a data protection inquiry does not depend on screenshots or manual exports: the record is queryable. OpenTelemetry export means the same traces that appear in an observability platform for engineering teams are available to a compliance function in its own tooling. The Analytics API adds usage data. Together these give the data protection record a live, queryable source for Claude-specific activity, which is the difference between a governance answer that holds under scrutiny and one that holds until a follow-up question arrives.

Frequently Asked Questions

Does Claude need to be enabled separately from the rest of Microsoft 365?
Yes, and the default depends on the tenancy type. Claude was enabled by default in most commercial Microsoft tenancies from 2026-01-07, but remains disabled by default in EU, EFTA, UK, government and sovereign tenancies. In those environments a tenant administrator has to enable it explicitly. The distinction matters because an organisation in an affected tenancy that deploys Claude without the explicit enablement step is running it outside the platform's own governance path, which is the harder answer to give an auditor.
Where does inference happen if the organisation is in the EU?
Anthropic has no native EU data residency. EU-only inference runs through one of three hosted paths: Microsoft Foundry, which keeps the call inside the Microsoft DPA already governing the tenant; AWS Bedrock with Claude in Frankfurt, Ireland or Paris; or Google Vertex AI. Each carries its own subprocessor agreement. A Data Processing Agreement is available for Anthropic Enterprise and API customers, and Standard Contractual Clauses cover EU-to-US transfers for direct API use. The residency path has to be selected before the first production call, not added to the architecture after a data protection officer raises it.
What is the difference between Claude Team and Claude Enterprise for a governance function?
The decisive difference is audit logs and SCIM. Claude Team, at $20 to $100 per seat per month, includes SSO, domain capture, admin controls, enterprise search and Claude Code, but carries no audit logs and no SCIM provisioning. Claude Enterprise, at $20 per seat plus API-rate usage, adds SCIM, audit logs, a Compliance API with programmatic access to activity logs, custom data retention and customer-managed encryption keys. Both plans exclude prompts from model training by default, without configuration. For an organisation that reports to a data protection function, the presence or absence of audit logs is usually the decision, not the seat price.
Are user prompts used to train the model?
No, for commercial plans. Claude Team, Claude Enterprise and direct API access all exclude prompts from model training by default. This is not a per-user setting and cannot be changed from the seat or the tenant side: the exclusion is the default position of the plan itself. A data protection impact assessment recording the training position does not need to caveat an opt-out mechanism, because none exists and none is required. This applies to the Anthropic API surface and to Claude as accessed through Microsoft Foundry, Copilot Studio and Microsoft 365 Copilot.
What does the Claude Partner Network signal for a buyer selecting an implementation partner?
The Claude Partner Network launched 2026-03-12 and includes a public services directory. Partner tiers are based on certified headcount, live deployments and public proof. The significance for an enterprise buyer is not the tier itself but what it signals: a listed partner is running Claude in production and has proof the network has examined. A directory search shows which practices exist, which markets they operate in and what kind of work they are associated with, which is a useful reference point when deciding whether to build the capability in-house or commission it.