# How to Connect Claude to Microsoft 365: Setup, Permissions & Fast Sync

Connecting Claude to Microsoft 365 allows Anthropic's AI models to access tenant documents, emails, and SharePoint sites through an authorized enterprise connector or an indexed MCP workspace. While the native connector searches OneDrive, Outlook, and Teams, it requires Microsoft Entra ID admin consent and can flood context windows with entire files. Synchronizing folders into an intelligent Fast.io workspace enables hybrid semantic search over remote MCP without token bloat.

Source: https://fast.io/resources/connect-claude-to-microsoft-365/
Author: [Tom Langridge](https://fast.io/authors/tom-langridge/)
Last reviewed: 2026-10-03

## How Claude Accesses Microsoft 365 Data and Files

Connecting Claude to Microsoft 365 exposes an immediate divide between standard chat connectors and high-throughput agent workflows. While Anthropic provides a native connector for Microsoft 365, enabling it requires navigating Microsoft Entra ID tenant consent, enterprise application registrations, and delegated Graph API permissions. Once connected, direct queries frequently encounter context window exhaustion because native tools pull full document payloads across rate-limited endpoints. The fix for teams managing extensive document libraries is not abandoning their existing SharePoint and OneDrive folder hierarchies, but pairing tenant authentication with an indexed cloud workspace that serves queries over the Model Context Protocol.

Connecting Claude to Microsoft 365 allows Anthropic's AI models to access tenant documents, emails, and SharePoint sites through an authorized enterprise connector or an indexed MCP workspace. Depending on whether your organization operates within a restricted corporate tenant or an agile multi-agent development environment, the integration architecture determines how files are authenticated, synchronized, and presented to Claude's context window.

```
+-------------------------------------------------------------------------+
|                        Claude Interface Layer                           |
|      (Claude Web, Claude Desktop, Claude Code, or Custom Agents)        |
+-------------------------------------------------------------------------+
         |                                                 |
 (Native M365 Connector)                         (Remote Workspace MCP)
         |                                                 |
  Microsoft Graph API                              Streamable HTTP /mcp
         |                                                 |
  Entra ID Tenant Consent                         Cloud Sync (Scheduled/On-Demand)
         |                                                 |
+---------------------------------+               +---------------------------------+
|      Microsoft 365 Tenant       |               |        Fast.io Workspace        |
|  - SharePoint Document Libraries| ------------> |  - Hybrid Semantic Indexing     |
|  - OneDrive for Business Files  |  (Cloud Sync) |  - Metadata Views Extraction    |
|  - Outlook Mail & Calendars     |               |  - Citation-Backed Search       |
|  - Teams Messages & Channels    |               |  - Per-File Version History     |
+---------------------------------+               +---------------------------------+
```

### The Four-Step Setup Sequence

Setting up an enterprise-grade connection between Claude and Microsoft 365 follows a four-step sequence:

1. Grant Azure AD tenant admin consent in the Microsoft Entra admin center or during initial administrator authentication.
2. Authenticate the Microsoft 365 connector in Claude under user settings.
3. Scope document library permissions across SharePoint sites and OneDrive user directories.
4. Connect via Fast.io remote MCP for indexed semantic file queries across synchronized document libraries.

### Three Methods for Integrating Microsoft 365 Files

Teams evaluating how to connect Claude to Microsoft 365 choose among three core integration patterns:

* **Native Microsoft 365 Connector:** Anthropic's hosted enterprise connector available inside Claude web and mobile applications. It connects through Microsoft Entra ID and uses delegated Graph API permissions to read emails, calendar appointments, Teams messages, OneDrive files, and SharePoint documents. This option requires an enterprise tenant and administrator consent, but it operates entirely within the Claude web interface without running local software.
* **Local Desktop Filesystem MCP:** Developers running Claude Desktop can configure the local filesystem Model Context Protocol server (`@modelcontextprotocol/server-filesystem`) pointed at a local folder synced by the OneDrive desktop client. While this provides direct file access on a single computer, it relies on local disk storage and fails whenever OneDrive Files On-Demand placeholders are encountered.
* **Remote Cloud Workspace MCP:** Synchronizing Microsoft 365 document libraries into an external, cloud-native workspace, such as a Fast.io workspace, and querying that workspace through a remote MCP server. In this pattern, your corporate files remain in OneDrive or SharePoint, while the workspace maintains an indexed replica. Claude queries the workspace over Streamable HTTP, retrieving targeted text passages and citations rather than streaming multi-megabyte files into active context.

For engineering teams building multi-agent workflows, [Fast.io storage for agents](/storage-for-agents/) provides dedicated workspace endpoints designed specifically for high-volume document retrieval.

## How to Configure Microsoft Entra Admin Consent and Permissions

Enabling the native Microsoft 365 connector requires strict administrative authorization before individual end users can link their accounts. Standard business users who attempt to toggle the connector in Claude settings without prior tenant approval will encounter permission errors.

### Account Type Requirements

The native Microsoft 365 connector functions exclusively with work accounts managed within a Microsoft Entra ID (formerly Azure Active Directory) tenant tied to a commercial Microsoft 365 Business or Enterprise plan. Personal Microsoft accounts registered with consumer domains cannot connect through the native integration.

Organizations running Claude Team or Enterprise plans must also have a Claude organization Owner enable the connector. The owner signs in to Claude, opens Organization settings, navigates to the Connectors section, selects Microsoft 365, and adds it to the team. On Free, Pro, and Max plans, individual users can initiate the connection directly once tenant consent is active.

### Granting Microsoft Entra Tenant Admin Consent

Before any employee can link their work account, a Microsoft Entra Global Administrator must authorize the integration for the tenant. Administrators can grant consent through one of two methods:

* **Consent Through Claude:** If the Global Administrator holds a seat on the Claude organization, they navigate to Customize, select Connectors, click Microsoft 365, choose Connect, and authenticate using their administrative credentials. During the Microsoft consent dialog, the administrator checks the box to grant consent on behalf of the entire organization. After this one-time approval, all other tenant members authenticate without seeing consent prompts.
* **Manual Service Principal Setup in Entra ID:** If the Entra administrator does not use Claude, or if corporate security policies require manual service principal registration, the administrator can register the integration directly via Microsoft Graph Explorer and consent URLs.

The integration relies on two distinct enterprise applications in Microsoft Entra ID:

1. **M365 MCP Client for Claude:** Registered under application ID `08ad6f98-a4f8-4635-bb8d-f1a3044760f0`.
2. **M365 MCP Server for Claude:** Registered under application ID `07c030f6-5743-41b7-ba00-0a6e85f37c17`.

Administrators add these service principals using Microsoft Graph Explorer by issuing `POST` requests to `https://graph.microsoft.com/v1.0/servicePrincipals` with the respective application IDs. Once added, the administrator visits the consent URL in a browser, replacing `{your-tenant-id}` with the organization's directory tenant ID:

```
https://login.microsoftonline.com/{your-tenant-id}/adminconsent?client_id=08ad6f98-a4f8-4635-bb8d-f1a3044760f0
https://login.microsoftonline.com/{your-tenant-id}/adminconsent?client_id=07c030f6-5743-41b7-ba00-0a6e85f37c17
```

### Delegated Permissions and Resource Scoping

The connector operates strictly on delegated permissions. Claude acts on behalf of the signed-in user and can only access documents, messages, and mailboxes that the specific user already has permission to read in Microsoft 365.

The default read-only permission set includes:

* **User Identity:** `User.Read`, `openid`, `offline_access`, `email`, and `profile`.
* **OneDrive and SharePoint:** `Files.Read`, `Files.Read.All`, and `Sites.Read.All`. These allow Claude to search files across personal OneDrive storage and shared SharePoint document libraries.
* **Outlook Mail and Calendar:** `Mail.Read`, `Mail.ReadBasic`, `Mail.Read.Shared`, `MailboxFolder.Read`, `MailboxItem.Read`, `MailboxSettings.Read`, `Calendars.Read`, and `Calendars.Read.Shared`.
* **Teams Communications:** `Chat.Read`, `Chat.ReadBasic`, `ChatMember.Read`, `ChatMessage.Read`, `Channel.ReadBasic.All`, and `ChannelMessage.Read.All`.
* **Meeting Intelligence:** `OnlineMeetings.Read`, `OnlineMeetingTranscript.Read.All`, and `OnlineMeetingArtifact.Read.All`.

To restrict access, Entra administrators can open the Entra portal, select Enterprise Applications, locate M365 MCP Server for Claude, and set Assignment Required to true under Properties. Adding specific security groups restricts authentication to approved departments. Individual permissions can also be selectively revoked under the Permissions tab, causing Claude to report tool execution errors if an unapproved resource is queried.

## Why Direct Microsoft 365 Connectors Hit Token and Rate Limits

While the native connector provides an accessible interface for individual questions, deploying it for intensive document analysis reveals significant technical friction. Competitors routinely gloss over these operational constraints, leading teams into unexpected performance bottlenecks.

### The Full Document Token Consumption Trap

The most severe operational issue with direct assistant connectors is token bloat. When a user asks Claude to analyze documents stored in SharePoint or OneDrive, the native connector uses Microsoft Graph search to locate matching files. Once identified, the connector fetches the entire document body and injects it directly into Claude's prompt context.

Consider an inquiry that requires comparing contract terms across multiple vendor agreements spanning dozens of pages. Fetching complete Word documents or PDF files transfers large volumes of tokens into prompt memory. This rapid consumption causes multiple problems:

* **Inference Cost Acceleration:** Every subsequent turn in the conversation carries the entire historical document payload, multiplying per-token inference charges.
* **Prompt Truncation and Attention Drift:** Context windows have finite boundaries. Filling active memory with redundant document prose degrades model focus, causing Claude to overlook specific instructions placed earlier in the prompt.
* **Tool Call Timeouts:** Transferring large file bodies over Graph API endpoints during a live chat turn introduces multi-second latency, frequently hitting client execution timeouts.

### Graph API Rate Limiting and Search Latency

Microsoft Graph enforces request throttling (HTTP 429 Too Many Requests) across enterprise tenants. When autonomous agents or multiple team members issue concurrent queries against large SharePoint libraries, Graph API rate limiters throttle traffic.

Unlike dedicated vector search engines, Microsoft Graph search is optimized for user-facing keyword queries, not high-frequency semantic filtering. Complex queries spanning thousands of nested folders often return partial results or time out entirely. Furthermore, email searches cover only primary mailboxes and Archive folders; messages archived into separate Online Archive mailboxes (In-Place Archives) are invisible to the connector.

### File Format Boundaries and Unsupported Data

The native connector reads a specific subset of standard file extensions:

* **Documents:** Word (`.docx`, `.doc`), Excel (`.xlsx`, `.xls`), and PowerPoint (`.pptx`, `.ppt`).
* **Portable Documents:** PDF files.
* **Structured Text:** `.txt`, `.md`, `.csv`, `.tsv`, `.json`, `.xml`, `.html`, and `.log`.

Files outside these extensions trigger validation errors. Microsoft OneNote notebooks (`.onetoc2`, `.one`) cannot be ingested directly by the connector, requiring manual conversion before Claude can parse meeting notes.

### Write Tool Limitations and Security Constraints

Anthropic supports optional write tools that permit Claude to draft emails, update calendar events, modify OneDrive files, and send Teams messages. However, write capabilities introduce corporate governance considerations:

* **Attribution Headers:** Emails transmitted by Claude include an automated header identifying the message as agent-initiated. File modifications, calendar entries, and Teams chat posts currently lack automated provenance tags.
* **No File Attachments:** Write tools reject messages containing attachments. Claude cannot forward an email with an attached invoice or dispatch a document review package through Outlook.
* **Team Governance:** Enabling write tools requires tenant administrators to re-consent to extended Graph scopes (`Mail.Send`, `Files.ReadWrite`, `Notes.Create`). In Claude organization settings, admins must configure Teams posting permissions on an individual tool basis.

## Comparing Direct Connectors to Workspace-Level MCP Retrieval

The architectural solution to context bloat and connector throttling is to separate corporate file storage from agent search infrastructure. Instead of forcing Claude to download full file binaries from Microsoft Graph during a prompt turn, organizations can synchronize their OneDrive and SharePoint folders into an intelligent cloud workspace.

In this architecture, Microsoft 365 remains your corporate system of record. Teams continue creating Word documents, managing spreadsheets, and sharing SharePoint folders exactly as they do today. A Fast.io workspace links to OneDrive via Cloud Sync, maintaining an indexed search replica in the cloud.

```
+------------------------------------+
|       Microsoft 365 Storage        |
|  - SharePoint Document Libraries   |
|  - Corporate OneDrive Folders      |
+------------------------------------+
                  |
                  | Cloud Sync (One-way or two-way, scheduled or on-demand)
                  v
+------------------------------------+
|         Fast.io Workspace          |
|  - Hybrid Full-Text + Vector Index |
|  - Metadata Views Data Extraction  |
+------------------------------------+
                  |
                  | Remote MCP over Streamable HTTP (/mcp)
                  v
+------------------------------------+
|          Claude Assistant          |
|  - Precise Paragraph Citations     |
|  - Sub-Second Retrieval Latency    |
|  - Zero Prompt Context Bloat       |
+------------------------------------+
```

### Cloud Sync Mechanics and Automated Indexing

Fast.io provides Cloud Sync for OneDrive, Box, and Dropbox. Folders can be kept in sync one-way or two-way, running on a recurring schedule or triggered on demand (Cloud Sync is never continuous, live, or real-time; SharePoint libraries are accessible through the OneDrive connector; Google Drive imports today with sync coming soon).

When documents sync into a Fast.io workspace, Intelligence Mode automatically indexes their contents. The system combines exact full-text keyword indexing with semantic vector retrieval. Document text, headings, tabular data, and metadata across PDFs, Office documents, presentations, and code files are processed into a hybrid search index.

When Claude needs information from your Microsoft 365 files, it does not download the original document or ingest whole files into prompt memory. Claude issues a targeted search query through the Fast.io remote MCP server. The workspace executes hybrid retrieval and returns only the matching passages alongside exact document names and page numbers.

### Measured Retrieval Performance

Decoupling file storage from agent retrieval also delivers major performance advantages. The connector comparison published at [Fast.io benchmarks](https://fast.io/benchmarks/) evaluates native assistant connectors against remote workspace architectures. In published benchmarks, Fastio was measured the fastest and the lowest cost of the providers tested. The benchmark evaluated provider native connectors in Claude Cowork across standard retrieval tasks, though SharePoint itself was not included in that measured cohort.

Serving pre-indexed text snippets instead of streaming raw document binaries across rate-limited consumer APIs eliminates connector stalls and context exhaustion.

### Structured Ingestion with Metadata Views

When managing structured document pipelines in Microsoft 365, such as purchase orders, legal filings, or quarterly performance reviews, semantic search can be paired with structured data extraction. Using [Fast.io Metadata Views](/product/document-data-extraction/), workspaces convert unstructured files into queryable spreadsheets.

Users describe the fields they want extracted in natural language, and the system establishes a typed schema covering Text, Integer, Decimal, Boolean, URL, JSON, and Date & Time formats. Incoming documents matched in the workspace populate a sortable, filterable spreadsheet grid. Claude can query these structured metadata fields directly through MCP, filtering files by exact parameters before retrieving body text.

## Steps to Connect Claude to Microsoft 365 via Remote MCP

Setting up remote MCP access allows Claude Desktop, Claude Code, and autonomous agent frameworks to interact with your synchronized Microsoft 365 content over a secure, authenticated endpoint.

### Step 1: Synchronize Microsoft 365 to a Fast.io Workspace

1. Sign in to your Fast.io organization account and create a dedicated workspace (for example, `m365-enterprise-docs`).
2. Open workspace settings, select Cloud Sync, and choose OneDrive as the provider.
3. Authenticate with your Microsoft 365 credentials (supporting commercial Microsoft 365 accounts as well as personal Microsoft accounts).
4. Select the specific OneDrive folders or SharePoint document libraries you want to synchronize.
5. Set your sync frequency (such as daily scheduled sync or manual on-demand sync).
6. Confirm that Intelligence Mode is active on the workspace so that incoming files are automatically indexed for hybrid search.

### Step 2: Configure Claude Desktop for Remote MCP

Unlike local filesystem tools that require local Node.js runtimes and physical directory paths, the Fast.io MCP server is hosted remotely over Streamable HTTP. Setup steps are detailed in the [Fast.io MCP documentation](https://mcp.fast.io/docs).

To connect Claude (web, desktop, mobile): open Customize, then Connectors; add a custom connector and paste `https://mcp.fast.io/mcp/tools`; select Connect and sign in to Fastio in the window that opens; in a chat, turn Fastio on from the + menu under Connectors.

Sign-in shows a Review Permissions screen where the person picks Read Only or Read & Write and which organizations and workspaces the connection can reach.

### Step 3: Querying Synchronized Documents in Claude

Once configured, Claude accesses your synchronized Microsoft 365 documents through a consolidated MCP toolset. Rather than cluttering Claude's prompt with dozens of specialized tools, the server exposes action-based tools.

Claude queries your files using the `storage` tool with the `search` action:

```json
{
  "tool": "storage",
  "action": "search",
  "params": {
    "query": "intellectual property indemnification cap",
    "files_scope": ["sharepoint-contracts-2026/"]
  }
}
```

The workspace executes the query and returns matching text passages with precise page citations. Claude synthesizes the answer using minimal tokens, leaving your context window open for subsequent analysis.

### Multi-Agent Coordination and Governance

For teams deploying autonomous agents alongside human knowledge workers, the workspace architecture provides essential governance features:

* **Per-File Version History:** When agents create or update files, every revision is preserved in version history, allowing human team members to inspect previous versions or roll back changes.
* **Advisory File Locks:** When multiple agents collaborate in a shared workspace, they coordinate writes using advisory file locks. An agent acquires a lock using `lock-acquire` and releases it with `lock-release` through the `storage_manage` tool, while verifying lock state via `lock-status` through the `storage` tool. Concurrent writes do not cause silent overwrites.
* **Activity Tracking:** Agents and human administrators can monitor workspace changes in real time. Rather than polling every file continuously, agents can subscribe to the workspace activity feed using the long-poll endpoint to react whenever new files are synchronized from Microsoft 365.
* **Ownership Transfer:** If an external agency or automated script builds out the workspace, organization ownership can be cleanly transferred to the client or company lead through a claim link, while the agent retains operational administrative access.

Monthly plans start with a 30-day free trial that requires a credit card, providing shared workspaces, Cloud Sync, and remote MCP connectivity as detailed on the [Fast.io pricing page](/pricing/).

| Subscription Tier | Monthly Billing | Annual Billing | Member Seats | Storage Capacity | Monthly Credits | Single File Upload Cap |
| --- | --- | --- | --- | --- | --- | --- |
| Starter | $9.99/mo | $99/year | 3 seats | 250 GB | 100,000 | 25 GB |
| Business | $49.99/mo | $499/year | 10 seats | 5 TB | 600,000 | 50 GB |
| Enterprise | $199.99/mo | $1,999/year | 30 seats included | 25 TB | 3,000,000 | 100 GB |

External guests who open a share link do not consume organization member seats, and additional storage beyond plan capacity is billed at 1.5 cents per GB monthly.

## Frequently asked questions

### How do I connect Claude to my Microsoft 365 account?

To connect Claude natively, an organization owner on a Team or Enterprise plan must first enable Microsoft 365 in Organization settings under Connectors. A Microsoft Entra Global Administrator must grant tenant-wide consent. Once consented, members navigate to Customize and select Connectors in Claude, choose Microsoft 365, and authenticate with their work account credentials. Alternatively, users can sync Microsoft 365 folders to an intelligent workspace and connect via remote MCP.

### Does Claude need admin consent to access SharePoint and OneDrive?

Yes, Claude requires Microsoft Entra ID Global Administrator consent before any user in a tenant can connect to SharePoint, OneDrive, Outlook, or Teams. The integration registers two enterprise applications (M365 MCP Client for Claude and M365 MCP Server for Claude) that require tenant-wide authorization for delegated Microsoft Graph permissions.

### Can Claude edit files directly in Microsoft 365?

Yes, if your tenant administrator has consented to updated write permissions and enabled write tools in Claude organization settings. With write tools enabled, Claude can create and update files in OneDrive and SharePoint, draft and send emails in Outlook, manage calendar events, and post messages in Teams. Write tools are subject to user limits, and emails sent by Claude include an automated agent-initiated header.

### Why does the native Claude Microsoft 365 connector reject personal accounts?

The native Microsoft 365 connector relies on enterprise Microsoft Entra ID application registrations and tenant consent mechanisms. Personal Microsoft accounts using consumer domains (@outlook.com, @hotmail.com, or @live.com) do not belong to an Entra tenant and cannot grant the delegated Graph API permissions required by the connector.

### How does remote workspace MCP prevent Claude context window exhaustion?

Direct connectors download complete file bodies into prompt memory during search turns, rapidly consuming context window capacity. A remote workspace MCP server indexes synchronized documents in advance using hybrid search. When Claude queries a topic, the workspace returns only relevant paragraphs and page citations, preserving prompt tokens for reasoning.

### Can Claude search multiple SharePoint document libraries at the same time?

Using the native connector, Claude can search across SharePoint sites where the authenticated user holds read permissions, but large queries risk Graph API throttling. By synchronizing multiple SharePoint document libraries into a Fast.io workspace, Claude can execute fast hybrid searches across all libraries simultaneously using the storage tool.

## Sources

- [Claude Help Center: Set up the Microsoft 365 connector](https://support.claude.com/en/articles/12542951-set-up-the-microsoft-365-connector): The native Microsoft 365 connector requires an enterprise Microsoft Entra tenant tied to a business plan and cannot be used with personal Microsoft accounts.
- [Claude Help Center: Connect to Microsoft 365](https://support.claude.com/en/articles/15183774-connect-to-microsoft-365): Personal Microsoft accounts cannot authenticate through the native Claude Microsoft 365 integration.

## About Fast.io

Fast.io provides shared workspaces where people and AI agents work on the same files, with built-in semantic search and citation-backed chat over what they hold. Agents reach it through a remote MCP server, a REST API at https://api.fast.io/current/, and a command line client published on npm as @vividengine/fastio-cli. MCP setup is at https://mcp.fast.io/docs: Claude and most MCP clients connect to https://mcp.fast.io/mcp/tools, ChatGPT to https://mcp.fast.io/mcp/operations, and coding agents to https://mcp.fast.io/mcp/code.
