It is 9:40 on a Tuesday. Your calendar is a wall of half-hour blocks. Outlook has three threads with the same vague subject line, SharePoint has a deck that is almost the final one, and your manager just asked for “a clean summary of where we landed on the Q3 plan.” You open Claude, because drafting that summary by hand will eat the only free hour you had. Then a second tab appears: Connect Microsoft 365. And a third thought: does my company even allow this?
This is Part 7 of Learn Claude from scratch. Parts 1 through 6 covered what Claude is, plans, first half hour, chats and Projects, everyday jobs, and memory and privacy. Here we stay light and practical about work: personal Pro habits versus work Team or Enterprise, connectors into Microsoft 365, and a safe loop you can run before anything leaves your drafts folder. This is a tour, not an enterprise admin manual. If your IT team has a written AI or data policy, that policy wins every time.
What you’ll learn
- How personal Pro, work Team or Enterprise, and connectors differ in plain language
- What “Claude for Microsoft 365” and the Microsoft 365 connector each do (and do not do)
- Why Entra admin consent shows up for mail, calendar, and file write tools
- A five-step safe loop: check policy, redact, draft, verify, human send
- Worked examples you can copy for status mail and meeting prep
- Common mistakes, a short practice drill, and where Claude Code and Cowork fit later
Three work setups people confuse
Most “Claude at work” confusion is really three different setups wearing the same logo.
| Setup | Who owns it | What it is good for | What to watch |
|---|---|---|---|
| Personal Pro (or Max) | You, on your own card | Side projects, learning, personal writing, some work if policy allows consumer tools | Company data rules still apply. “I paid for it” is not approval. |
| Team / Enterprise | Your org (billing, seats, admins) | Shared standards, SSO options, org connectors, admin on/off switches | You work inside company policy. Owners can enable or remove tools for everyone. |
| Connectors + M365 features | You plus IT (and often Entra admins) | Search or act on mail, files, calendar, Teams context you already can see | Consent, licenses, and write tools are separate gates. Personal Microsoft accounts usually fail. |
Pro is still a paid path that includes access toward Microsoft 365 features Anthropic ships for paid plans (add-ins and related product paths change over time; check current plan pages). Team and Enterprise are the org products: seats, owner settings, and the kind of controls Security expects. Connectors are the glue that pulls workplace context into Claude. You can have Pro without a work connector. You can have Team without anyone granting Microsoft consent. Treat them as layers, not as one blob labeled “work mode.”
Rule of thumb: If the account is on your personal email and the credit card is yours, assume Security sees a consumer tool until someone says otherwise in writing.
A light map of Claude near Microsoft 365
Two product ideas get mixed in Slack threads. Both are real in 2026. They solve different friction.

Claude for Microsoft 365 (in the Office apps)
Anthropic’s Claude for Microsoft 365 path is about working inside the apps many of us already live in: Excel, PowerPoint, Word, and Outlook (availability and beta status can differ by app and plan). The pitch is practical: edit and reason over the file in front of you, carry context across those apps when the feature is enabled, and keep a human in control of what gets saved or sent.
On Team and Enterprise, org owners often have an extra switch before people can let Claude work across files or apps. On personal paid plans, defaults can be looser. That is a product design choice, not a free pass on company documents. If the deck is confidential, treat Claude the same way you would treat any other assistant with eyes on the slides.
The Microsoft 365 connector (from Claude outward)
The Microsoft 365 connector is the other direction: you are in Claude (web or product surfaces that support connectors), and you ask it to pull context from SharePoint, OneDrive, Outlook, and Teams using your existing permissions. Anthropic documents this as a connector available across Free, Pro, Max, Team, and Enterprise, with important setup gates for work tenants.
From Anthropic’s admin help (July 2026 framing):
- You need a Microsoft Entra tenant tied to a Microsoft Business plan. Personal @outlook.com / @hotmail.com style accounts are not the path.
- On Team and Enterprise, a Claude org owner enables the connector for the organization.
- A Microsoft Entra Global Administrator grants one-time consent so people in the tenant can connect.
- Write tools (send mail, manage calendar events, create or update files, and related write scopes) need an updated consent set plus org enablement. Read and search can work without write tools.
- Claude uses delegated permissions: it acts as you, and only on data you could already reach in Microsoft 365.
That last bullet is the part people skip. A connector is not a master key to the company. It is a long arm that reaches only as far as your own badge already goes. If you should not open that SharePoint folder in a browser, Claude should not open it for you either.
IT and policy first (boring on purpose)
Before you connect anything, spend ten minutes on the unsexy layer.
- Search your intranet for “AI policy,” “acceptable use,” “Claude,” “ChatGPT,” or “third-party AI.”
- Ask whether consumer AI tools are allowed with company data, banned, or limited to approved enterprise plans.
- If you are on Team or Enterprise already, ask who the Claude owner is and which connectors are on.
- If connect fails with “admin must grant consent,” stop recruiting coworkers to click through. That is an Entra admin job, not a peer pressure job.
- If write tools are blocked, treat that as intentional until IT says otherwise. Draft-only is still useful.
Security teams are not being dramatic when they care about Graph scopes for Mail.Send or Files.ReadWrite.All. Those permissions change what “help me with this” can become: send, create, update. Anthropic’s own help notes that agent-sent email can include attribution headers, that write tools have per-user limits, and that some surfaces (like Teams message posting) stay out of scope. Details move; the habit does not: know whether you are in read mode or write mode before you ask for action.
Not legal advice, not security certification. This post is operator hygiene. Contracts, industry rules, and your employer’s policies decide what is allowed. When those disagree with a blog tutorial, follow your employer.
The safe loop for work drafts
Here is the loop I want you to muscle-memory before any connector or add-in makes sending feel easy.

| Step | What you do | What “done” looks like |
|---|---|---|
| 1. Check policy | Confirm tool, plan, and data class are allowed | You know: approved enterprise path, personal tool with limits, or stop |
| 2. Redact | Strip or fake names, emails, account ids, secrets, unreleased numbers | The prompt would not embarrass you in a public channel |
| 3. Draft | Ask Claude for structure, wording, options, or a summary of allowed context | You have text or a plan still labeled as a draft |
| 4. Verify | Check facts, tone, recipients, dates, links, and numbers against ground truth | You could defend every claim if your boss asked “where is that from?” |
| 5. Human send | You (or the real owner) click send, share, or schedule | Claude did not become the final actor by accident |
Write tools make step 5 the place people slip. “Draft an email to myself, don’t send” is a good test when IT turns writes on. “Summarize these three threads and send the team a recap” is a different risk class. Keep the human click for anything external or anything that creates a permanent record in someone else’s inbox.
If you do analysis work, the same loop pairs with the check habits from the practical AI series and the SQL audit post: How to check AI-written SQL before you ship it. Fluency is not correctness. Models are good at sounding done. Work needs done-and-true.
What “good at work” looks like day to day
Meeting prep without inventing the room
Paste (or connect, if allowed) only what you already would put in a private notes doc. Ask for:
- A one-page agenda with time boxes
- Open questions grouped by owner
- A “what would make this meeting a waste” list so you can cut fluff
Do not ask Claude to invent what Legal or Finance decided last Thursday unless that decision is in the materials you gave it. If the connector pulls a stale deck, you still own the version check.
Status mail that sounds like you
Give Claude three bullets you already believe, plus audience and length. Ask for two tones: crisp and slightly warmer. Pick one. Edit the first sentence by hand so it matches how you actually write. People can smell a full-body swap to corporate-smooth voice.
File cleanup in Word or Excel
Inside Claude for Microsoft 365 surfaces, good jobs look like: tighten this section, propose a cleaner table layout, explain what this formula is doing, draft speaker notes from the slide bullets. Bad jobs look like: invent last quarter’s revenue, fill missing cells with plausible numbers, or “fix” a model you have not opened in the finance system of record.
Worked example: status update with the safe loop
Scenario: you need a Friday update to your manager about a migration project. You have notes in OneNote and two tickets. Policy allows an approved Claude path with no customer personal data.
Step 1, policy: company allows Team Claude for internal project text. No customer PII in prompts.
Step 2, redact: you rewrite ticket titles to drop customer names. “Acme Corp outage” becomes “Customer A outage (retail vertical).”
Step 3, draft prompt (you can paste this pattern):
Audience: my manager (busy, wants risk + next week)
Length: under 180 words
Tone: plain, no hype
Facts I already verified:
- Cutover window moved from Sat 10pm to Sun 2am local (vendor constraint)
- 14 of 16 services green in staging as of Thursday 4pm
- Two services still flaky: billing-export, notify-worker
- Blocker: waiting on network allowlist from infra (ticket INFRA-1842)
- Ask: 30 min Monday to decide go / no-go
Write a status email with: done this week, risks, ask.
Do not invent metrics or owners I did not list.
Label the draft as DRAFT in the first line.Step 4, verify: you check the cutover time against the vendor email, confirm the ticket number, and make sure “14 of 16” is still true this morning. You delete a smooth sentence Claude added about “strong stakeholder alignment” because you never said that.
Step 5, human send: you copy into Outlook, add the real subject line, and send yourself. Claude does not press send.
That is a boring win. Boring wins are the point at work.
Worked example: connector search without overreach
Suppose the connector is approved and write tools are off. You ask:
Search my recent email and the Q3 planning SharePoint folder for
messages or docs about the vendor cutover window.
Summarize only what you find. Quote dates. If nothing recent,
say so. Do not propose a new cutover time.Good outcomes: a short list of sources with dates, or an honest “nothing after June 12.” Bad outcomes: a confident new plan stitched from two old decks and one rumor in a Teams chat. Your verify step is opening the linked sources. If you cannot open them, the summary is not shippable.
Personal Pro versus work Team or Enterprise
Use this decision table when someone asks “should I just buy Pro?”
| Situation | Lean personal Pro / Max | Lean Team / Enterprise |
|---|---|---|
| Learning Claude, personal writing, side projects | Yes | Optional |
| Company data, customer text, unreleased numbers | Only if written policy allows consumer tools | Usually the intended path |
| You need SSO, seat management, audit story for Security | Weak fit | Strong fit |
| You need org-wide connector on/off and role controls | Limited | Designed for this |
| You want Microsoft 365 features on a paid Claude plan | Possible on paid personal plans per product pages | Same features, with org switches and admin story |
Paying personally can still be smart for skills practice. Paying personally does not license you to feed the CRM export into a consumer chat. Part 6 of this series (memory, privacy, and what never to paste) still applies when the logo on the tab is Claude and the data is your employer’s.
A tiny “prompt kit” for work without connectors
No connector? You can still work carefully with redacted paste and Projects (Part 4).
Context: internal project only, no customer PII.
Role: help me structure work, not invent facts.
If a number or decision is missing, ask me. Do not fill gaps.
Output: bullet plan + risks + open questions.
I will verify against our tracker before sharing.Keep a Project instruction file with your team’s glossary (what “P0” means, how you name environments, who owns go/no-go). That beats re-explaining culture every Monday.
Common mistakes
- Treating connect success as policy approval. OAuth working means credentials worked, not that Legal signed off.
- Using a personal Microsoft account for a work connector. Entra business tenants are the documented path; personal consumer accounts fail the model.
- Assuming write tools are on because read search works. Write scopes are a separate consent and enablement story.
- Skipping verify on numbers and dates. Fluent wrong is still wrong, and email makes it permanent.
- Letting Claude send “because the draft looked fine.” Keep human send for external and high-stakes internal mail.
- Pasting secrets into chat to “debug faster.” API keys, connection strings, and tokens never belong in prompts.
- Confusing Claude with your system of record. ERP, warehouse, ticketing, and HR systems stay authoritative.
- Shadow IT heroics. Five people on personal Pro with customer data is not a clever workaround. It is an incident waiting for a ticket.
Practice: 25 minutes
- Find your company AI or acceptable use page (or note that none exists and escalate politely).
- Write five lines on whether you are on personal Pro, Team, Enterprise, or none.
- Without connecting anything, run the status email prompt above with fake project facts. Practice the verify step by changing one number and seeing if you catch it.
- If connectors are allowed, ask IT which tools are read-only versus write-enabled. Save the answer next to your other access notes.
- Add the safe loop to your personal checklist for anything that might leave the building.
A peek at agentic products (tease only)
Claude is not only a chat box. Anthropic also ships agentic products on paid paths, notably Claude Code (coding-oriented agent workflows) and Claude Cowork (agent-style help aimed at broader desktop and file work). Those are different risk and skill surfaces than “draft my status email.” We only name them here so the map stays honest. Deeper coverage lives in the later series on the Claude product map, Claude Code, and Cowork. For everyday work mail and docs, stay with chat, Projects, connectors, and the Office add-in path until you have a clear use case and policy green light.
How this fits the rest of AMS
If you use Claude for analytics text, SQL drafts, or chart critique, keep the practical AI series habits: define the job, give the right context, and check outputs against reality. The SQL check tutorial is the model for “fluent is not finished”: How to check AI-written SQL before you ship it. For broader AI work patterns, start from the Learn hub: Learn.
Quick recap
- Separate personal Pro, org Team/Enterprise, and connectors. They are layers.
- Claude for Microsoft 365 works inside Office apps; the connector pulls M365 context into Claude.
- Entra admin consent and write-tool enablement are real gates. Do not social-engineer them.
- Run check policy → redact → draft → verify → human send every time it matters.
- Delegated permissions mean Claude inherits your access, not infinite access.
- Models stay fluent and fallible. You stay the sender of record.
Next: Part 8 closes this series with judgment: when Claude is the wrong tool, a good-enough checklist, and where the product map and agentic series go next.
Sources
Product pages and help used for this article (features and defaults change; verify against current docs before you roll anything out):
- Anthropic: Claude for Microsoft 365 (product overview for Office app workflows)
- Anthropic: Microsoft 365 connector (SharePoint, OneDrive, Outlook, Teams context in Claude)
- Claude Help Center: Set up the Microsoft 365 connector (Entra consent, org enablement, write tools)
- Claude Help Center: Microsoft 365 connector security guide (delegated permissions, security model)
- Claude Help Center: Work across Microsoft 365 apps (cross-app settings and Team/Enterprise owner controls)
- Anthropic: Plans and pricing (what paid plans include, including Microsoft 365-related features as listed)
- Anthropic: Claude Enterprise (org security and deployment framing)
- Analytics Made Simple: How to check AI-written SQL before you ship it (verify habit for fluent but wrong outputs)
- Analytics Made Simple: Learn (related paths on this site)
