AI Enterprise AI Configuration Board

Configuration board for IT, MSP, security, legal, compliance, and business owners

Enterprise AI choices, made explicit.

This is an IT design menu for two standalone deployment options: a direct Anthropic Claude organization and Microsoft 365 Copilot native. It does not define the firm's policy. It shows the concrete product settings, Microsoft controls, technical tradeoffs, and ownership decisions required before rollout.

Direct Claude starting configurations

IT Lens

The firm brings the regulatory judgment. This board brings the control map: where Claude has an admin setting, where Microsoft 365 is the real enforcement point, and where policy or process has to fill the gap.

Start with the product boundary

Direct Claude and Microsoft 365 Copilot can both provide access to Anthropic models, but they use different tenants, administrators, storage paths, monitoring feeds, and permission systems. The first decision is which control plane the firm is ordering.

Keep identity and data access separate

Entra decides who may sign in or use Microsoft-connected applications. Microsoft 365 permissions decide which business content a user can reach. Claude or Copilot settings then decide which AI capabilities can act on that access.

Map each activity to its actual telemetry

Claude Chat, local Cowork, cloud Cowork, Claude in Chrome, Microsoft Graph activity, Copilot Chat, Copilot Cowork, and agents do not all appear in the same logs. The control map below makes each documented feed, limitation, and transition explicit.

What Changed Since the Last Review

This ledger separates current documented product behavior from configuration decisions the client still needs to make. Release state matters: generally available, preview, rolling rollout, future-effective, and documentation-conflict items are labeled instead of blended together.

Choose the Deployment Architecture

These are separate deployment options. Selecting one changes which configuration menu and locked-path inventory are shown; selecting both keeps each control plane distinct.

Microsoft 365 Copilot Native Menu

Applies when Microsoft 365 Copilot, Copilot Chat, Microsoft agents, or Copilot Cowork are the deployment product. Microsoft 365, Entra, Copilot Control System, Cost Management, Integrated Apps, Agent Registry or Agent 365, and Purview are the control plane.

Anthropic model access inside Copilot is a Microsoft AI-provider setting. It does not create a Claude Team or Enterprise organization, and the Direct Claude settings above do not govern it.

Locked Path Inventories

These tabs assume the plan choice has already been made. The inventory is deliberately long: it is a client-owned spec capture sheet so implementation technicians are not left to choose defaults.

Control Coverage Map

This map describes the technical source of control and visibility. It does not characterize whether any combination satisfies a firm requirement.

Activity surface Primary administrator Primary storage location Claude audit / Compliance API Cowork OTel Microsoft Purview / audit Endpoint visibility
Direct Claude Chat and Projects Claude organization Anthropic service Enterprise: audit and Compliance API
Team: product analytics and admin surfaces
Not applicable Enterprise preview connector: DSPM and audit only Sign-in, browser, and device controls only
Claude Cowork local session Claude organization plus device management User device; code runs in a local isolated VM Architecture guide says not captured Primary documented local activity feed Do not assume Purview connector coverage Host EDR cannot inspect inside the VM
Claude Cowork cloud session Claude organization; Enterprise custom roles can gate cloud access Anthropic cloud session and member account New support page says web/mobile cloud sessions are captured; architecture guide conflicts Configure where supported; verify actual event coverage Do not assume connector ingestion until tested Execution runs outside the endpoint
Claude in Chrome Claude organization plus Chrome deployment owner Claude service plus the user's browser session Direct-Claude records where documented; model controls do not yet apply Not a Cowork OTel surface Depends on direct-Claude connector coverage Managed extension, site policy, and endpoint controls
Claude Microsoft 365 connector Claude owner plus Entra administrator M365 source remains in tenant; retrieved results can enter Claude chats Claude conversation and tool records where supported When invoked through local or cloud Cowork Microsoft Graph operations in M365 audit Authentication and device posture
Microsoft 365 Copilot Chat Microsoft 365 and Copilot administrators Microsoft 365 service and hidden Exchange mailbox locations Not a direct Claude feed Not applicable Purview audit, retention, and licensed controls Microsoft app and device controls
Copilot Cowork service tasks Microsoft 365 Copilot administrators plus Cost Management policy owners Temporary isolated M365 service-boundary environment; task files removed after processing Not a direct Claude feed Not Claude Cowork OTel Audit, eDiscovery, labels, lifecycle, insider risk, and communication compliance; AI-interaction DLP not supported Service task runs outside the endpoint
Copilot Cowork local browser Microsoft 365 Copilot and Edge administrators User's local Edge work profile and existing signed-in sessions Not a direct Claude feed Not Claude Cowork OTel Browser-task and related Cowork audit events Edge, Conditional Access, DLP, and site policy
Copilot Cowork scheduled or automated tasks Microsoft 365 Copilot administrators and task owner Microsoft 365 service plus task artifacts in their destination services Not a direct Claude feed Not applicable Scheduled-task, prompt, response, and action events where documented Only when a task uses a local browser or device surface
Microsoft agents, plugins, and MCP connectors Microsoft 365 Agent Registry, Integrated Apps, Agent 365, and Power Platform Depends on agent, plugin, channel, and connected data source Not a direct Claude feed Not applicable Agent, plugin, and connector events vary by surface Depends on execution channel

Suggested Combos

These are starting points for the meeting, not final policy positions.

Balanced enterprise rollout

Enterprise plan, Entra SSO/SCIM, role groups, curated products and models, export-first records path, read-only M365 pilot, needs-approval tool policy, central skills and plugins, cloud Cowork pilot with mode-specific telemetry validation, controlled builders, and wave rollout.

Minimum surface

Enterprise plan, strict Entra groups, no M365 connector at launch, Cowork off, central skills only, manual direct-Claude review, managed-device access, and a small invite wave.

Builder enablement

Enterprise plan with role-targeted products and models, controlled builder roles, reviewed skills and plugins, local and cloud Cowork, dev/test API workspaces, approved connector tools, higher spend caps, mode-specific telemetry, and promotion gates for repeatable workflows.

Implementation Runbook

The MSP can run this once the firm's internal owners select the menu posture.

Step What gets configured Owner to involve
1. Lock the deployment architecture Select Direct Claude, Microsoft 365 Copilot native, or both. Record the tenant IDs, products, license paths, user populations, administrators, and whether Anthropic models are accessed directly, through Copilot, or both. Business sponsor, IT, vendor owner
2. Build identity and role groups Verify domains and Entra groups. For Direct Claude, configure SSO, JIT or SCIM, Claude groups, custom roles, product capabilities, model access, and defaults. For Copilot, configure licenses, app access, provider groups, Cowork discovery groups, spending-policy groups, and agent-maker groups. IT, MSP, security
3. Configure storage and evidence paths Map direct Claude retention, audit and Compliance API; local Cowork history and OTel; cloud Cowork account storage and the documented Compliance API conflict test; Microsoft Copilot retention, Cowork Activity Explorer, unified audit, eDiscovery, and unsupported Cowork AI-interaction controls; then name the destination and reviewer for each selected feed. Information management, IT, security operations
4. Configure Microsoft data access For the Direct Claude connector, set both Entra app assignments, exact Graph read scopes, optional write scopes, and tool approvals. For native Copilot, review work-grounding permissions, SharePoint readiness, labels, DLP, and app surfaces. IT, security, compliance
5. Configure agentic execution For Claude Cowork, select local, cloud, or both plus plan defaults, custom-role access, network, MDM, persistent approval, plugin, scheduled-task, trusted-device, and mode-specific monitoring settings. For Copilot Cowork and agents, configure the M365 Copilot license, discovery, Copilot Credit policies, actions, session approvals, schedules, models, plugins, Edge browsing, MCP connectors, maker rights, Registry or Agent 365, submission, publication, and deployment. IT, security, endpoint, Power Platform
6. Publish the enablement pack Publish product-specific user guidance, Direct Claude organization instructions, skills, plugin catalog, model and surface guidance, Copilot prompts, skill/plugin catalog, action and scheduling guidance, request paths for connectors or agents, and support routing that distinguishes the two products. Business owner, IT, enablement owner
7. Verify and expand by evidence Test allowed and blocked identities, product and model access, content access, read and write actions, local and cloud execution, telemetry, Copilot Credit policy precedence, Purview capability claims, plugin authentication, scheduled tasks, incident shutdown controls, and web, mobile, desktop, and browser surfaces before adding groups or capabilities. Store the evidence with the approved configuration. Steering group

Product Sources

Source links are limited to technical product controls. The July 31 change ledger uses newly reviewed sources; carried-forward sources retain the prior board review date. The firm's legal and compliance team should map these settings to their own policies and obligations.