The Claude Microsoft 365 connector used to be a search tool. Claude could read your Outlook mail, your SharePoint sites, your OneDrive files, and your Teams threads, and that was the whole story. Anything that changed the state of your tenant was off the table. That just changed.

Claude can now send email, move things to the trash, book and cancel meetings, set your out-of-office, rewrite inbox rules, and create, rename, move, and delete files in SharePoint and OneDrive. But it ships off by default, and switching it on requires two separate approvals in two different places. Here is exactly what's new, what's still missing, and what an admin has to do.

What the Microsoft 365 connector can actually do now

More than 30 new tools were added. They land in four buckets.

microsoft 365 · 30+ write tools
Email
  • Send, forward, and send an existing draft
  • Create drafts, including reply and reply-all
  • Update and delete drafts
  • Move conversations to Deleted Items
  • Batch-delete messages, and restore them
Calendar
  • Create, update, and delete events
  • Accept invitations on your behalf
  • Decline or tentatively accept
Mailbox settings
  • Create and delete inbox rules
  • Set your automatic out-of-office reply
  • Create, rename, recolor, and delete categories
  • Apply categories across messages or whole threads
Files
  • Upload new files to SharePoint and OneDrive
  • Replace the contents of existing ones
  • Create folders
  • Rename, move, copy, and delete files and folders

30+ tools across four areas. Every one of them changes something in your tenant.

The delete options are real, and they are worth pausing on. Mail goes to Deleted Items and files go to the Recycle Bin, so nothing here is unrecoverable. But Claude can absolutely clear out your inbox and reorganize a SharePoint library, and "recoverable" is not the same as "no big deal" when the library in question is the one your whole team works out of.

The read-only connector told you what was in your inbox. This one can empty it.

What it still can't do

Three gaps matter, and one of them will break a workflow you probably already had in mind.

Claude can now
  • Send, forward, and draft Outlook mail
  • Book, change, and cancel calendar events
  • Rewrite inbox rules and set out-of-office
  • Create, move, and delete SharePoint and OneDrive files
Claude still can't
  • Post in Teams. It reads chats and channels, but there is no tool to send a message or change a setting
  • Attach a file to an email. Every write tool rejects messages with attachments, including drafts
  • Exceed your own access. Delegated permissions mean Claude acts as you, and your DLP policies still apply

Teams is read-only. Email attachments are blocked entirely. Everything else is gated by your own permissions.

The attachment gap is the one to plan around. If your workflow is "pull the report and email it to the client," Claude handles the first half and stops. It cannot send, forward, or even draft an email with a file attached. Put the file in SharePoint and have Claude send the link instead, or expect to do the last step by hand.

The delegated-permissions model is the part that should make security teams breathe easier. Claude is not a service account with its own reach. It is you, with your access, hitting the same Graph endpoints you would hit through Outlook. A SharePoint site you can't see is a site Claude can't write to.

The safeguards that come with it

Anthropic built in a handful of controls. Most are reassuring. One is a gap worth flagging to whoever owns compliance in your org.

1Sent email gets taggedEmails Claude sends carry a header identifying them as agent-initiated.
!Calendar and file writes are not taggedSomeone reviewing a modified SharePoint file has no signal that Claude touched it rather than a person. This is the gap.
2The riskiest actions can't be pre-approved"Always allow" is blocked for sending email, forwarding, sending a draft, and creating or updating calendar events. You approve those every single time.
3Rate limits apply per userThere are caps on writes, sends, and recipient counts.
4Everything hits your audit logAll Graph API calls the connector makes are logged in your Microsoft 365 audit log with timestamp, user, operation, and resource, viewable in the Compliance Center.

Four safeguards and one hole: file and calendar changes carry no agent marker.

Before you flip the switch

Permissions are the easy part. Knowing what to hand Claude is the hard part.

An admin can turn write tools on in ten minutes. Deciding which work actually belongs with an AI teammate, and where a human check has to stay, takes a bit more. Our free Cowork Masterclass walks through building that setup step by step, from your first connected tool to a workflow your team can trust.

Free · Self-paced · 26 short lessons

Turning it on takes two approvals

There are two separate gates, in two different places, and both have to happen before anyone in your org sees a write tool.

Gate 1 · Microsoft Entra Global Admin re-consents Approve the updated permission set through your tenant's Enterprise Applications consent flow. One time per tenant.
Gate 2 · Claude Enable write tools in org settings Organization settings > Connectors > Microsoft 365. Blocked by default even after the Entra consent goes through.
Then · Test Try something harmless Anthropic's own suggestion: "Draft an email to myself, but don't send it." If that works, you're live.

Both gates, in order. Missing either one is why most orgs still see a read-only connector.

Gate one is the one people get stuck on. The write tools need Graph scopes the connector never asked for before:

Mail.Send Mail.ReadWrite Calendars.ReadWrite Files.ReadWrite.All MailboxSettings.ReadWrite

If your tenant consented back when the connector was read-only, that old consent does not cover any of these. A Microsoft Entra Global Administrator has to review and approve the updated permission set. It's a one-time action per tenant, and it is the single most common reason a team thinks the feature "isn't available yet."

Gate two lives on the Claude side. Go to Organization settings, then Connectors, find Microsoft 365, and set the permissions. On Enterprise plans you can scope write access to a subset of people using custom roles instead of flipping it on for everybody, which is the sane way to pilot this.

If you're a user and you don't see write tools

Check three things, in order:

You also get your own controls once it's on. Under Customize > Connectors > Microsoft 365 there's a Tool permissions list where you can turn individual tools off. Keep document search, kill email writes, whatever fits how you actually work.

30+
New write tools added
2
Separate approvals required
0
Teams write tools so far

The bottom line

The read-only version of this connector was useful. Claude could find the thread, summarize the file, and tell you what was waiting for you. This version is a different thing entirely: it closes the loop between "here's what needs doing" and the doing.

That's worth having, and it's worth being deliberate about. Turn it on scoped to a small group first, leave the approval prompts in place on sends and calendar writes, and keep an eye on the fact that file changes arrive in SharePoint with no marker saying an agent made them. The audit log is your backstop, so make sure somebody actually knows how to read it.