Key Takeaways — Claude in Microsoft 365 Copilot
  • Claude Sonnet and Claude Opus are now selectable models inside Copilot Chat, Researcher, and Copilot Studio — not a separate product bolted on the side.
  • Turning Anthropic on as a Microsoft subprocessor switches the model on. It does not automatically switch on Purview data loss prevention, audit logging, or insider risk detection.
  • Microsoft Agent 365, generally available since May 2026, now includes Anthropic Claude in its cross-platform agent registry alongside Copilot Studio and endpoint agents.
  • Standalone Claude Enterprise deployments can reach the same compliance visibility through Anthropic's Claude Compliance API — but only if someone configures it.
  • The decision that matters isn't "Copilot or Claude" — it's whether Claude usage, wherever it happens, ends up inside your governance perimeter or outside it.

Claude in Microsoft 365 Copilot has quietly become one of the more consequential changes to hit enterprise AI in 2026. Since Microsoft began rolling out Anthropic's models across Copilot Chat, Researcher, and Copilot Studio, the practical question for IT and security leaders has shifted. It is no longer whether Claude is capable enough for work — it clearly is — but whether your organisation can see what it is doing once it's there.

Most conversations about "Copilot vs standalone AI tools" still get framed as a productivity comparison: which interface is faster, which model writes better, which one your staff already prefer. That framing misses the part that actually determines risk exposure. The same Claude model can sit inside two completely different governance postures depending on how it's accessed, and the gap between those postures is where incidents happen.

What "Claude Inside Copilot" Actually Means Today

Microsoft's multi-model strategy for Copilot is no longer a pilot. Anthropic models first appeared in Researcher and Copilot Studio, then extended into Copilot Chat during the first quarter of 2026, with Anthropic onboarded as a formal Microsoft subprocessor rather than an independent processor. Microsoft's documentation now lists Anthropic model availability across Microsoft Copilot, Researcher, Copilot Studio, Power Platform, and Copilot in Microsoft 365 apps. Microsoft has since renamed Microsoft 365 Copilot to Microsoft Copilot, and Microsoft 365 Copilot Chat to Microsoft Copilot Chat, with no change to the underlying security or compliance posture.

That subprocessor status matters more than it sounds. Under the arrangement, the Microsoft Product Terms, the Microsoft Data Protection Addendum, and Enterprise Data Protection apply to Anthropic model use, and the Microsoft Customer Copyright Commitment extends to Anthropic models in covered products. What it does not do is place that traffic inside every data boundary your organisation may rely on. Microsoft states plainly that Anthropic models in these offerings are currently excluded from the EU Data Boundary and, where applicable, from in-country processing commitments — a distinction any organisation with data residency obligations should document before enabling the setting.

⚠️

Regional defaults are not consistent: Anthropic models are on by default for most commercial cloud tenants, but EU, EFTA, and UK tenants have them disabled by default. Microsoft decommissioned the old Anthropic "independent processor" toggle on 1 May 2026, and organisations that previously opted in under Anthropic's separate terms must opt in again. Government cloud availability is narrower still: non-federal GCC customers gained an opt-in setting on 22 July 2026, while federal GCC, GCC High, DoD, and other sovereign cloud customers cannot use Anthropic models at all.

There is a second category most governance conversations miss entirely. Anthropic's newest frontier models are offered inside Microsoft Online Services as Preview models with Data Retention, and for those specific models Anthropic acts as an independent data processor, not a Microsoft subprocessor. They sit outside your Microsoft Customer Agreement, Product Terms, and DPA commitments, they remain default-off even in tenants where Anthropic is otherwise enabled, and the admin must explicitly accept Anthropic's own commercial terms to turn them on. If your organisation runs on a blanket assumption that Copilot is covered by the Microsoft agreement, this is the exception to it.

Where Claude Shows Up Inside the Copilot Estate

Claude doesn't appear in one place inside Microsoft 365 — it shows up across several surfaces, each with a different governance posture attached. Knowing which surface your staff are actually using is the first step to closing the visibility gap, because "we've enabled Copilot" tells you almost nothing about which of these four entry points is active.

Surface 01
Copilot Chat & Researcher
Native tenant identity
High Visibility
Surface 02
Copilot Studio Agents
Agent 365 registry
High Visibility
Surface 03
Edit with Copilot (Word, Excel, PowerPoint)
Region-dependent default
Medium Visibility
Surface 04
Standalone Claude (web, desktop, mobile, CLI)
Outside tenant unless wired in
Low Visibility

The Five Governance Gaps We See Most Often

In every environment we assess, the same pattern of gaps shows up around AI model adoption. None of these are exotic — they're the predictable result of a security setting being switched on faster than the governance work around it gets done.

  1. 01

    Unmanaged access outside the tenant boundary

    Staff reaching Claude directly bypass Entra identity, conditional access, and your Purview reporting entirely. This isn't only a browser problem: the desktop app, the mobile app, and Claude Code on the command line all sit outside the tenant unless you deliberately bring them in. The model itself isn't the risk. The fact that none of your existing controls ever see the session is.
  2. 02

    Agents that never make the inventory

    Copilot Studio agents built on Claude land in your Agent 365 registry automatically. A Claude-powered workflow stitched together outside that stack — a script, a browser extension, a third-party tool — typically doesn't, leaving IT with an incomplete picture of what's actually running.
  3. 03

    Assuming one admin toggle covers every surface

    Anthropic access is governed in more than one place. The tenant-level subprocessor setting sits in the Microsoft 365 admin centre, a separate setting controls Copilot in Microsoft 365 apps for EU, EFTA, and UK tenants, and Copilot Studio and Power Platform need their own external LLM permission in the Power Platform admin centre. Admins who check one and assume consistency are usually wrong.
  4. 04

    Treating "subprocessor enabled" as "governed"

    Switching Anthropic on as a subprocessor makes the model available. It does not turn on DLP policies, insider risk signals, or audit logging for that traffic — those are separate configurations inside Purview that require deliberate setup.
  5. 05

    Standalone Claude Enterprise rollouts skipping the compliance layer

    This is the one teams miss most often, precisely because it looks like the safer path. Anthropic's Claude Compliance API can feed Claude Enterprise activity into Microsoft Purview, CrowdStrike, Okta, and two dozen other platforms most mid-market firms already run. Few standalone deployments actually connect it, so the enterprise tier ends up no more visible than the consumer one — and connecting it takes deliberate setup, including pay-as-you-go billing on the Purview side.

Enabling Anthropic as a subprocessor turns a model on. It doesn't turn on governance — that's still a decision your admin console has to make deliberately.

— Robert Kirtley, Head of Cyber Security · Virtuelle Group
Free Discovery Call
Not sure which Claude your organisation is actually running?
Book a 30-minute, no-commitment call and we'll walk through your tenant's current Anthropic subprocessor, Copilot, and Purview settings together. No sales pitch — just a clear picture of where Claude access sits inside or outside your governance perimeter. Our team works out of Sydney, Melbourne, Singapore, and Chicago.
Book a Free Discovery Call

What Agent 365 and Purview Now See That They Didn't in 2025

The governance side of this equation moved fast. Microsoft Agent 365 reached general availability for commercial customers on 1 May 2026, positioned as the control plane to observe, govern, and secure agents — Microsoft's own three-word framing. It's included in Microsoft 365 E7 or available standalone at USD 15 per user per month, with each licence covering a person who manages, sponsors, or is served by agents.

Two capabilities matter directly for Claude. Agent 365 registry sync, launched in public preview at GA with Amazon Bedrock and Google Cloud connections, has since expanded its supported platform list to include Anthropic Claude, Databricks Genie, and Salesforce Agentforce — pulling externally built agents into one inventory alongside Microsoft-native ones. Separately, Microsoft Defender and Intune are gaining discovery and blocking for local AI agents running on Windows devices, starting with OpenClaw and expanding to GitHub Copilot CLI and Claude Code. Treat the local agent controls as an emerging capability rather than something to build a policy around today.

Microsoft Purview moved in parallel. On 21 May 2026, Anthropic launched a Claude Compliance API with 28 enterprise security and compliance integrations spanning DLP, SASE, SIEM, identity, and eDiscovery — Microsoft Purview among them, alongside CrowdStrike, Okta, Zscaler, Netskope, and Palo Alto Networks. Microsoft now documents a dedicated Anthropic Claude connector for Purview, which brings Claude Enterprise interactions into DSPM, activity explorer, auditing, Insider Risk Management, communication compliance, and eDiscovery.

🧩

The nuance most vendors skip: the Purview Anthropic Claude connector is currently in preview, requires pay-as-you-go billing to be enabled, and does not support every Purview capability. Data loss prevention, sensitivity labels, and encryption without sensitivity labels are all listed as unsupported for Claude interactions today, and there are no one-click DSPM policies for Anthropic Claude — you monitor through Reports, activity explorer, and the Apps and agents dashboard instead. Claude agents also don't yet appear in AI observability.

What the connector does capture is more than many assume. Prompts and responses are written to the unified audit log the same way other activities are, and that data surfaces in activity explorer under the AI activities tab. For compliance investigations and eDiscovery, that's a real evidence base — it just isn't a preventative control, which is the distinction that matters when someone asks whether Claude usage is "protected."

20+
Years Microsoft Security Practice
28
Platforms in Claude's Compliance API
$15
Per User, Standalone Agent 365
100%
Your Data Stays Governed

Those numbers tell a consistent story: the governance tooling caught up to model availability faster than most organisations' internal processes did. The 28-platform figure and the Agent 365 price come from Anthropic's and Microsoft's own May 2026 announcements — both worth confirming with your Microsoft or Anthropic account team before budgeting, since licensing and preview scope continue to move.

🏁

Our recommendation: if Claude is already active in your tenant, don't stop at the subprocessor toggle. Check the Power Platform admin centre controls that govern Anthropic use in Copilot Studio and Power Platform, confirm whether Preview models with Data Retention are enabled, and set up the Purview Anthropic Claude connector if standalone Claude Enterprise is in play. Model availability and model oversight are separate admin actions, and only the first one happens by default.

Who Should Run Claude Through Copilot vs Standalone

This isn't a universal answer, and any vendor telling you it is hasn't looked closely enough at how different teams actually use these tools. The right path depends on who's using Claude and for what.

Financial services, healthcare, and professional services organisations generally get more value from Claude inside Copilot, because the governance controls — Entra identity, conditional access, Purview auditing — are already part of the tenant they operate every day. Government is the exception worth stating clearly: Anthropic models aren't available to federal GCC, GCC High, DoD, or other sovereign cloud customers at all, and non-federal GCC customers who enable them should note Microsoft's own warning that this processes data outside the FedRAMP-authorised US Government cloud. Technology and engineering teams often need standalone Claude Enterprise or Claude Code for capabilities Copilot doesn't expose, which is a legitimate choice as long as the Compliance API connection gets built alongside the rollout rather than after an audit finds the gap.

  • Check the Anthropic subprocessor setting in the Microsoft 365 admin centre, then check the separate Power Platform admin centre control for Copilot Studio
  • Confirm whether Preview models with Data Retention are enabled — these fall outside your Microsoft agreement and are default-off for a reason
  • Review your Purview reporting through activity explorer's AI activities tab, and understand which capabilities are supported for Claude and which aren't
  • Add Claude to your Agent 365 registry and inventory review alongside Copilot Studio and endpoint agents
  • For any standalone Claude Enterprise deployment, connect the Compliance API to Purview or your SIEM before go-live, not after
💼

Sharing this on LinkedIn? The line worth tagging your CISO or IT Manager on is this one: enabling a model isn't the same as governing it — and that gap is exactly where most AI incidents originate. Share this article →

Three Questions to Ask Before You Choose a Path

Before your organisation locks in a position on Copilot-native Claude versus standalone Claude Enterprise, three questions cut through most of the noise. First: which specific Copilot surfaces have Anthropic switched on right now, and did anyone check that after Microsoft's independent processor setting was decommissioned in May 2026? Second: if a standalone Claude deployment already exists, is the Compliance API actually connected, or is it running as invisible shadow AI with an enterprise contract attached? Third: does your Purview DSPM configuration treat Claude traffic the same way it treats OpenAI traffic, or does one model get monitored and the other doesn't?

None of these questions require replacing your AI strategy. They require a half-day audit of settings that already exist in your tenant, most of which were switched on by default or by a well-meaning admin trying to give staff more model choice. The organisations getting this right aren't the ones avoiding Claude — they're the ones who know exactly where it's running and who's watching.

VG
Virtuelle Group Security Practice
Microsoft-Certified MSSP · Sydney, Australia
Virtuelle Group is a Microsoft-certified Managed IT and Cybersecurity partner headquartered in Sydney with offices in Melbourne, Singapore, and Chicago. Our security practice specialises in Microsoft 365 Copilot governance, Anthropic Claude and multi-model AI security, Microsoft Purview DSPM configuration, Essential Eight compliance, and managed SOC services. We work with SMB to enterprise clients across financial services, healthcare, government, and professional services.