Follow Discord
Sweep 08 Oct 2026 · 18:53Z Build v2.1.295 516 read Stable v2.1.286 Latest v2.1.295 Next v2.1.295 Feeds RSS JSON llms.txt llms-full.txt Unofficial
One change · claude-docs

Connect to Microsoft 365 changedthird-party/claude-desktop/connectors-m365

Nearest release: v2.1.283, published an hour after upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.

Upstream edited this page at 25 Sep 2026 17:09 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 28 Sep 2026 22:07 UTC.

Upstream edited
Recorded here
Lines+105added
Lines−105removed
From line 12 where the diff opens
First seen 14 Aug 2026 this site's first read of the page
Recorded edits13to this page, all time

The whole hunk

from line 12, old and new numbered
/
lines
from line 12
1212 
1313Both connectors provide the same read and search tools; they differ in data path and authentication. Write actions (sending mail, managing drafts and calendar events, working with files, and sending Teams messages) are available on the local connector when you grant [write scopes](#grant-write-scopes). For write actions on the remote connector, contact your Anthropic representative. Use this table to pick one, then follow that connector's section below.
1414 
15| | Remote connector | Local connector |
16| ------------------------------- | ------------------------------------------------------------------------ | --------------------------------------------------------------------- |
17| Microsoft 365 data path | Transits Anthropic's infrastructure (no storage) | Stays between the user's device and Microsoft |
18| App registrations you own | One desktop client app, plus tenant consent to Anthropic's connector app | One dedicated public client app |
19| Token exchange | On-behalf-of exchange in Anthropic's infrastructure | Tokens acquired and stored on the device |
20| Allowlisting with Anthropic | Required (two to three business days) | Not needed |
21| Device egress | `login.microsoftonline.com` and the connector host | `login.microsoftonline.com` and `graph.microsoft.com` |
22| Device-based Conditional Access | Not supported (the server-side exchange has no device identity) | Supported on managed Windows and Mac devices through brokered sign-in |
23| Write actions | Contact your Anthropic representative | Available with [write scopes](#grant-write-scopes) |
24| US Government clouds | Separate connector deployment; contact your Anthropic representative | Built in; set `azureCloud` |
15| | Remote connector | Local connector |
16| - | - | - |
17| Microsoft 365 data path | Transits Anthropic's infrastructure (no storage) | Stays between the user's device and Microsoft |
18| App registrations you own | One desktop client app, plus tenant consent to Anthropic's connector app | One dedicated public client app |
19| Token exchange | On-behalf-of exchange in Anthropic's infrastructure | Tokens acquired and stored on the device |
20| Allowlisting with Anthropic | Required (two to three business days) | Not needed |
21| Device egress | `login.microsoftonline.com` and the connector host | `login.microsoftonline.com` and `graph.microsoft.com` |
22| Device-based Conditional Access | Not supported (the server-side exchange has no device identity) | Supported on managed Windows and Mac devices through brokered sign-in |
23| Write actions | Contact your Anthropic representative | Available with [write scopes](#grant-write-scopes) |
24| US Government clouds | Separate connector deployment; contact your Anthropic representative | Built in; set `azureCloud` |
2525 
2626## Remote connector
2727 
from line 35
3535 
3636Three applications participate in the sign-in chain. Understanding which one each ID refers to makes the setup steps below easier to follow.
3737 
38| Application | Owner | Purpose |
39| ----------------------- | ------------------------------- | ---------------------------------------------------------------------------- |
40| Desktop client app | You (registered in your tenant) | What Claude Desktop signs in as. Public client, PKCE, no secret. |
41| Anthropic connector app | Anthropic (multi-tenant) | Receives the desktop's token and calls Microsoft Graph on the user's behalf. |
42| Microsoft Graph | Microsoft | The Microsoft 365 data APIs. |
38| Application | Owner | Purpose |
39| - | - | - |
40| Desktop client app | You (registered in your tenant) | What Claude Desktop signs in as. Public client, PKCE, no secret. |
41| Anthropic connector app | Anthropic (multi-tenant) | Receives the desktop's token and calls Microsoft Graph on the user's behalf. |
42| Microsoft Graph | Microsoft | The Microsoft 365 data APIs. |
4343 
4444Claude Desktop signs in through your desktop client app, receives a token scoped to the Anthropic connector app, and sends that token to Anthropic's connector service. The connector service exchanges it for a Graph token using the on-behalf-of flow and makes Graph calls as the signed-in user.
4545 
from line 59
5959 
6060 The consent screen lists the delegated Microsoft Graph permissions the connector requests. All are read-only:
6161 
62 | Scope | Purpose |
63 | ----------------------------------------- | ----------------------------------------------------------- |
64 | `User.Read` | Read the signed-in user's profile |
65 | `Mail.Read`, `Mail.Read.Shared` | Read mail in the user's and shared mailboxes |
66 | `Calendars.Read`, `Calendars.Read.Shared` | Read events in the user's and shared calendars |
67 | `Files.Read.All` | Read files the user can access in OneDrive and SharePoint |
68 | `Sites.Read.All` | Read SharePoint site content the user can access |
69 | `Chat.Read`, `ChatMessage.Read` | Read Teams chat messages the user can access |
70 | `offline_access` | Allow the desktop to refresh its token without re-prompting |
62 | Scope | Purpose |
63 | - | - |
64 | `User.Read` | Read the signed-in user's profile |
65 | `Mail.Read`, `Mail.Read.Shared` | Read mail in the user's and shared mailboxes |
66 | `Calendars.Read`, `Calendars.Read.Shared` | Read events in the user's and shared calendars |
67 | `Files.Read.All` | Read files the user can access in OneDrive and SharePoint |
68 | `Sites.Read.All` | Read SharePoint site content the user can access |
69 | `Chat.Read`, `ChatMessage.Read` | Read Teams chat messages the user can access |
70 | `offline_access` | Allow the desktop to refresh its token without re-prompting |
7171 
7272 Review the permissions and select **Accept**.
7373 
from line 99
9999 <Step title="Configure Claude Desktop">
100100 In the Claude Desktop [in-app configuration window](/docs/third-party/claude-desktop/in-app-configuration), open **Connectors**, select **Add server → Microsoft 365**, and enter the values below.
101101 
102 | Field | Value |
103 | --------- | -------------------------------------------------------------------------- |
104 | Client ID | The Application (client) ID from step 2 |
105 | Tenant ID | Your Directory (tenant) ID |
106 | Scope | `api://07c030f6-5743-41b7-ba00-0a6e85f37c17/access_as_user offline_access` |
102 | Field | Value |
103 | - | - |
104 | Client ID | The Application (client) ID from step 2 |
105 | Tenant ID | Your Directory (tenant) ID |
106 | Scope | `api://07c030f6-5743-41b7-ba00-0a6e85f37c17/access_as_user offline_access` |
107107 
108108 Select **Save**, then deploy the configuration through your device-management tool as usual.
109109 
from line 132
132132 
133133In addition to the [base egress hosts](/docs/third-party/claude-desktop/telemetry#required-egress-paths), Claude Desktop needs outbound HTTPS access to the hosts below. The connector service itself calls `graph.microsoft.com` from Anthropic's infrastructure, so user devices do not need egress to Graph.
134134 
135| Host | Purpose |
136| ----------------------------- | ------------------------------------------------------------- |
137| `login.microsoftonline.com` | Microsoft Entra sign-in |
135| Host | Purpose |
136| - | - |
137| `login.microsoftonline.com` | Microsoft Entra sign-in |
138138| `microsoft365.mcp.claude.com` | The connector service (substitute your deployment's hostname) |
139139 
140140### Troubleshoot sign-in errors
from line 141
141141 
142142The errors below are the ones most commonly seen during setup. Each maps to a specific step that was missed or misconfigured.
143143 
144| Error | Cause | Fix |
145| -------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------- | --------------------------------- |
146| `AADSTS50011` redirect mismatch | Redirect URI is not exactly `http://127.0.0.1/callback`, or was registered under *Web* instead of *Mobile and desktop applications* | Re-check step 2.1 |
147| `AADSTS50194` multi-tenant required | Tenant ID is missing from the configuration | Add Tenant ID in step 4 |
148| `AADSTS65001` admin consent required | Step 1 was not completed, or step 2.4 was skipped | Complete admin consent |
149| `Client application is not authorized for this resource` | Anthropic allowlist not yet updated | Wait for confirmation from step 3 |
150| `AADSTS9000411` duplicate prompt parameter | Older Claude Desktop build | Upgrade to the current release |
144| Error | Cause | Fix |
145| - | - | - |
146| `AADSTS50011` redirect mismatch | Redirect URI is not exactly `http://127.0.0.1/callback`, or was registered under *Web* instead of *Mobile and desktop applications* | Re-check step 2.1 |
147| `AADSTS50194` multi-tenant required | Tenant ID is missing from the configuration | Add Tenant ID in step 4 |
148| `AADSTS65001` admin consent required | Step 1 was not completed, or step 2.4 was skipped | Complete admin consent |
149| `Client application is not authorized for this resource` | Anthropic allowlist not yet updated | Wait for confirmation from step 3 |
150| `AADSTS9000411` duplicate prompt parameter | Older Claude Desktop build | Upgrade to the current release |
151151 
152152## Local connector
153153 
from line 173
173173 <Step title="Configure Claude Desktop">
174174 In the Claude Desktop [in-app configuration window](/docs/third-party/claude-desktop/in-app-configuration), open **Connectors**, select **Add server**, and choose **Microsoft 365** under the **Built-in** group. Enter the values below, then select **Test connection** to verify that the server starts and lists its tools, and select **Save**.
175175 
176 | Field | Value |
177 | ----------- | ----------------------------------------------------------------------------------------------------------- |
178 | Tenant ID | Your Directory (tenant) ID |
179 | Client ID | The Application (client) ID from step 1 |
180 | Azure cloud | `global` (default), `us-gov-high`, or `us-gov-dod` |
181 | Access | Leave empty for standard read access, or list scopes explicitly (see [Configure scopes](#configure-scopes)) |
176 | Field | Value |
177 | - | - |
178 | Tenant ID | Your Directory (tenant) ID |
179 | Client ID | The Application (client) ID from step 1 |
180 | Azure cloud | `global` (default), `us-gov-high`, or `us-gov-dod` |
181 | Access | Leave empty for standard read access, or list scopes explicitly (see [Configure scopes](#configure-scopes)) |
182182 
183183 If you manage configuration through JSON or a plist directly, add an entry to [`managedMcpServers`](/docs/third-party/claude-desktop/configuration#managedmcpservers) with the `server` field set to `microsoft365`:
184184 
from line 191
191191 }
192192 ```
193193 
194 | Field | Required | Description |
195 | ---------------------------- | -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
196 | `name` | Yes | Unique display name, shown to users in connector settings. |
197 | `server` | Yes | Must be `microsoft365`. Built-in entries use this field instead of `url`, `transport`, or `command`; an entry that mixes `server` with those fields is rejected. |
198 | `clientId` | Yes | The Application (client) ID of the local-mode app from step 1. |
199 | `tenantId` | Yes | Your Directory (tenant) ID. |
200 | `azureCloud` | No | `global` (default), `us-gov-high`, or `us-gov-dod`. Selects the Microsoft Entra and Microsoft Graph hosts for US Government clouds. |
201 | `continuousAccessEvaluation` | No | `enabled` (default) or `disabled`. When enabled, the connector requests Continuous Access Evaluation-capable Microsoft Graph tokens, which live up to about 28 hours and stop working within minutes after an administrator revokes the user's sessions or disables the account in Entra, and, where your tenant enforces an IP named-location or Global Secure Access compliant-network Conditional Access policy, when the token is used from outside that network. `disabled` keeps standard one-hour tokens. A change applies to tokens issued after the connector next starts, and an already-issued token stays in use until it expires (select **Disconnect**, then **Connect**, to sign in again immediately). Requires Claude Desktop 1.49585.0 or later; earlier versions ignore the field and request standard one-hour tokens. |
202 | `scope` | No | Space-separated delegated Graph scopes to request instead of the default read set. A string array named `scopes` is also accepted until October 7, 2026. See [Configure scopes](#configure-scopes). |
203 | `toolPolicy` | No | Per-tool approval locks, the same as for any managed server. See [`toolPolicy`](/docs/third-party/claude-desktop/configuration#managedmcpservers). |
194 | Field | Required | Description |
195 | - | - | - |
196 | `name` | Yes | Unique display name, shown to users in connector settings. |
197 | `server` | Yes | Must be `microsoft365`. Built-in entries use this field instead of `url`, `transport`, or `command`; an entry that mixes `server` with those fields is rejected. |
198 | `clientId` | Yes | The Application (client) ID of the local-mode app from step 1. |
199 | `tenantId` | Yes | Your Directory (tenant) ID. |
200 | `azureCloud` | No | `global` (default), `us-gov-high`, or `us-gov-dod`. Selects the Microsoft Entra and Microsoft Graph hosts for US Government clouds. |
201 | `continuousAccessEvaluation` | No | `enabled` (default) or `disabled`. When enabled, the connector requests Continuous Access Evaluation-capable Microsoft Graph tokens, which live up to about 28 hours and stop working within minutes after an administrator revokes the user's sessions or disables the account in Entra, and, where your tenant enforces an IP named-location or Global Secure Access compliant-network Conditional Access policy, when the token is used from outside that network. `disabled` keeps standard one-hour tokens. A change applies to tokens issued after the connector next starts, and an already-issued token stays in use until it expires (select **Disconnect**, then **Connect**, to sign in again immediately). Requires Claude Desktop 1.49585.0 or later; earlier versions ignore the field and request standard one-hour tokens. |
202 | `scope` | No | Space-separated delegated Graph scopes to request instead of the default read set. A string array named `scopes` is also accepted until October 7, 2026. See [Configure scopes](#configure-scopes). |
203 | `toolPolicy` | No | Per-tool approval locks, the same as for any managed server. See [`toolPolicy`](/docs/third-party/claude-desktop/configuration#managedmcpservers). |
204204 
205205 The server ships inside the app, so nothing else needs to be installed on the device, and it activates only from managed configuration; users cannot add it themselves. Deploy the configuration through your device-management tool as usual.
206206 </Step>
from line 208
208208 <Step title="Allow the required network hosts for local mode">
209209 The local connector calls Microsoft directly from the device, so in addition to the [base egress hosts](/docs/third-party/claude-desktop/telemetry#required-egress-paths), devices need outbound HTTPS access to:
210210 
211 | Host | Purpose |
212 | --------------------------- | ------------------------- |
213 | `login.microsoftonline.com` | Microsoft Entra sign-in |
214 | `graph.microsoft.com` | Microsoft Graph data APIs |
211 | Host | Purpose |
212 | - | - |
213 | `login.microsoftonline.com` | Microsoft Entra sign-in |
214 | `graph.microsoft.com` | Microsoft Graph data APIs |
215215 
216216 US Government cloud deployments use `login.microsoftonline.us` and `graph.microsoft.us` (or `dod-graph.microsoft.us` for `us-gov-dod`) instead, matching the `azureCloud` setting. GCC High (`us-gov-high`) support has been confirmed in customer deployments. No egress to any Anthropic host is needed for Microsoft 365 data with the local connector.
217217 </Step>
from line 221
221221 
222222With no `scope` field, the connector requests the standard read set at sign-in:
223223 
224| Scope | Purpose |
225| ----------------------------------------- | ---------------------------------------------------------------------- |
226| `User.Read` | Read the signed-in user's profile |
227| `Mail.Read`, `Mail.Read.Shared` | Read mail in the user's and shared mailboxes |
224| Scope | Purpose |
225| - | - |
226| `User.Read` | Read the signed-in user's profile |
227| `Mail.Read`, `Mail.Read.Shared` | Read mail in the user's and shared mailboxes |
228228| `Calendars.Read`, `Calendars.Read.Shared` | Read events in the user's and shared calendars, and find meeting times |
229| `Files.Read.All` | Read files the user can access in OneDrive and SharePoint |
230| `Sites.Read.All` | Read SharePoint site content the user can access |
231| `Chat.Read` | Read Teams chat messages the user can access |
232| `OnlineMeetings.Read` | Read the user's online meetings |
233| `offline_access` | Refresh tokens without re-prompting |
229| `Files.Read.All` | Read files the user can access in OneDrive and SharePoint |
230| `Sites.Read.All` | Read SharePoint site content the user can access |
231| `Chat.Read` | Read Teams chat messages the user can access |
232| `OnlineMeetings.Read` | Read the user's online meetings |
233| `offline_access` | Refresh tokens without re-prompting |
234234 
235235To request a different set, list scopes in the entry's `scope` field. The connector then requests exactly that list (plus `User.Read` and `offline_access`, which are always included). Use the list to narrow the read surface, to add the optional read scopes below, or to add [write scopes](#grant-write-scopes). Whatever you list must also be consented on the app registration from step 1; keep the two lists in sync.
236236 
from line 252
252252 
253253The connector provides these read and search tools:
254254 
255| Tool | What it does |
256| ----------------------------------------------- | --------------------------------------------------------------------------------------------------- |
257| `outlook_email_search` | Search Outlook mail |
258| `outlook_calendar_search` | Search calendar events |
259| `find_meeting_availability` | Find free meeting times |
260| `outlook_find_available_time` | Find open time slots for a meeting between the user and specific participants |
261| `chat_message_search` | Search Teams chat (1:1 and group; channel messages need `ChannelMessage.Read.All`) |
262| `sharepoint_search`, `sharepoint_folder_search` | Search SharePoint and OneDrive |
263| `read_resource` | Fetch a specific item, such as a message, event, or file |
264| `teams_list_chats` | List the user's Teams chats and their members, to find a chat to read or post in |
265| `get_me` | Return the signed-in user's own profile |
266| `search_people` | Search for people by name or email address (needs `People.Read`) |
267| `teams_list_teams`, `teams_list_channels` | List the user's teams and a team's channels (need `Team.ReadBasic.All` and `Channel.ReadBasic.All`) |
268| `teams_list_channel_messages` | List a channel's messages, or the replies in one conversation (needs `ChannelMessage.Read.All`) |
255| Tool | What it does |
256| - | - |
257| `outlook_email_search` | Search Outlook mail |
258| `outlook_calendar_search` | Search calendar events |
259| `find_meeting_availability` | Find free meeting times |
260| `outlook_find_available_time` | Find open time slots for a meeting between the user and specific participants |
261| `chat_message_search` | Search Teams chat (1:1 and group; channel messages need `ChannelMessage.Read.All`) |
262| `sharepoint_search`, `sharepoint_folder_search` | Search SharePoint and OneDrive |
263| `read_resource` | Fetch a specific item, such as a message, event, or file |
264| `teams_list_chats` | List the user's Teams chats and their members, to find a chat to read or post in |
265| `get_me` | Return the signed-in user's own profile |
266| `search_people` | Search for people by name or email address (needs `People.Read`) |
267| `teams_list_teams`, `teams_list_channels` | List the user's teams and a team's channels (need `Team.ReadBasic.All` and `Channel.ReadBasic.All`) |
268| `teams_list_channel_messages` | List a channel's messages, or the replies in one conversation (needs `ChannelMessage.Read.All`) |
269269 
270270Granting write scopes enables write tools; see [Grant write scopes](#grant-write-scopes).
271271 
from line 273
273273 
274274With only read scopes granted, the connector is read-only. To let Claude take actions in Microsoft 365 (sending mail, managing drafts, labels, and calendar events, working with files in OneDrive and SharePoint, and sending Teams chat and channel messages), grant write scopes: add them to the entry's `scope` field and consent them on the app registration from step 1, the same as any other scope. Each write tool appears only when its scope is in the entry's list, so granting a subset of the write scopes exposes a matching subset of the tools, and removing the write scopes from the list returns the connector to read-only. Write tools require Claude Desktop version 1.19367.0 or later, and the Teams write tools require version 1.24012.0 or later.
275275 
276| Scope | What it enables |
277| --------------------------- | ------------------------------------------------------------------------------------------------------------- |
278| `Mail.Send` | Send mail, send drafts, and forward mail |
279| `Mail.ReadWrite` | Create, update, and delete drafts; trash, untrash, and delete messages; apply and remove labels on messages |
280| `Calendars.ReadWrite` | Create, update, delete, and respond to calendar events |
281| `Files.ReadWrite.All` | Create, update, rename, move, copy, and delete files and folders the user can edit in OneDrive and SharePoint |
282| `MailboxSettings.ReadWrite` | Create and delete mail filters, manage labels, and configure automatic replies |
283| `ChatMessage.Send` | Post messages in existing Teams chats |
284| `ChannelMessage.Send` | Post and reply to messages in Teams channels |
285| `Chat.Create` | Start 1:1 and group Teams chats |
276| Scope | What it enables |
277| - | - |
278| `Mail.Send` | Send mail, send drafts, and forward mail |
279| `Mail.ReadWrite` | Create, update, and delete drafts; trash, untrash, and delete messages; apply and remove labels on messages |
280| `Calendars.ReadWrite` | Create, update, delete, and respond to calendar events |
281| `Files.ReadWrite.All` | Create, update, rename, move, copy, and delete files and folders the user can edit in OneDrive and SharePoint |
282| `MailboxSettings.ReadWrite` | Create and delete mail filters, manage labels, and configure automatic replies |
283| `ChatMessage.Send` | Post messages in existing Teams chats |
284| `ChannelMessage.Send` | Post and reply to messages in Teams channels |
285| `Chat.Create` | Start 1:1 and group Teams chats |
286286 
287287Sending drafts and forwarding mail also require a mail read scope (one of `Mail.Read`, `Mail.ReadWrite`, or `Mail.Read.Shared`) for the pre-send checks; the standard read set already includes one.
288288 
from line 341
341341 
342342### Troubleshoot the local connector
343343 
344| Symptom | Cause | Fix |
345| ----------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------- |
346| **Test connection** reports that the built-in server is not included | The installed Claude Desktop version predates the built-in connector | Upgrade Claude Desktop |
347| **Microsoft 365** is missing from the **Add server** options | The installed Claude Desktop version predates the built-in connector | Upgrade Claude Desktop, or author the JSON entry directly |
348| Connector missing from settings | The entry was rejected during configuration parsing: an unrecognized scope name in `scope`, a missing `tenantId` or `clientId`, or a `url`, `transport`, or `command` field mixed into the entry | Check the app's main log for a line naming the dropped entry |
349| Sign-in opens the browser on a managed device where the broker was expected | macOS: Claude Desktop is older than 1.19367.0, Company Portal is not installed, the SSO configuration profile is not deployed, or the broker redirect URI is not registered. Windows: Claude Desktop is older than 1.13576.0, the device is not Entra-joined or Entra-registered, or `microsoftAuthBroker` is set to `disabled` | Re-check the brokered sign-in requirements above |
350| `AADSTS50011` redirect mismatch | The redirect URI named in the error message (`http://localhost` for browser sign-in, or the platform's broker redirect URI for brokered sign-in) is missing from the local-mode app registration, was entered with a different value, or was added under *Web* instead of *Mobile and desktop applications* | Add or correct that URI under *Mobile and desktop applications* (step 1.2, or the brokered sign-in requirements above) |
351| `AADSTS900971` no reply address provided | The macOS broker redirect URI is not registered on the local-mode app | Register `msauth.com.anthropic.claudefordesktop://auth` as described in step 1.2 (after you save, it appears under the **iOS / macOS** section) |
352| `AADSTS65001` admin consent required | Graph delegated permissions were not admin-consented | Re-check step 1.4 |
353| `AADSTS53003` blocked by Conditional Access | A device-compliance policy is evaluating a sign-in that carries no device claim | Meet the brokered sign-in requirements for the platform, then restart Claude Desktop |
354| `AADSTS7000218` request body must contain client\_assertion or client\_secret | **Allow public client flows** is set to No on the local-mode app registration, so brokered token requests are classified as confidential | Set **Allow public client flows** to **Yes** (step 1.3) |
355| Tools return a permission error or Graph `403` | A scope the tool needs is not consented on the app registration, or is excluded by an explicit `scope` list | Add the scope in both places and grant admin consent |
356| Write tools are missing or fail | The matching write scope is not listed in the entry's `scope` field, or the installed Claude Desktop version predates write support | Add the scope to the entry and consent it on the app registration (see [Grant write scopes](#grant-write-scopes)), and upgrade Claude Desktop |
344| Symptom | Cause | Fix |
345| - | - | - |
346| **Test connection** reports that the built-in server is not included | The installed Claude Desktop version predates the built-in connector | Upgrade Claude Desktop |
347| **Microsoft 365** is missing from the **Add server** options | The installed Claude Desktop version predates the built-in connector | Upgrade Claude Desktop, or author the JSON entry directly |
348| Connector missing from settings | The entry was rejected during configuration parsing: an unrecognized scope name in `scope`, a missing `tenantId` or `clientId`, or a `url`, `transport`, or `command` field mixed into the entry | Check the app's main log for a line naming the dropped entry |
349| Sign-in opens the browser on a managed device where the broker was expected | macOS: Claude Desktop is older than 1.19367.0, Company Portal is not installed, the SSO configuration profile is not deployed, or the broker redirect URI is not registered. Windows: Claude Desktop is older than 1.13576.0, the device is not Entra-joined or Entra-registered, or `microsoftAuthBroker` is set to `disabled` | Re-check the brokered sign-in requirements above |
350| `AADSTS50011` redirect mismatch | The redirect URI named in the error message (`http://localhost` for browser sign-in, or the platform's broker redirect URI for brokered sign-in) is missing from the local-mode app registration, was entered with a different value, or was added under *Web* instead of *Mobile and desktop applications* | Add or correct that URI under *Mobile and desktop applications* (step 1.2, or the brokered sign-in requirements above) |
351| `AADSTS900971` no reply address provided | The macOS broker redirect URI is not registered on the local-mode app | Register `msauth.com.anthropic.claudefordesktop://auth` as described in step 1.2 (after you save, it appears under the **iOS / macOS** section) |
352| `AADSTS65001` admin consent required | Graph delegated permissions were not admin-consented | Re-check step 1.4 |
353| `AADSTS53003` blocked by Conditional Access | A device-compliance policy is evaluating a sign-in that carries no device claim | Meet the brokered sign-in requirements for the platform, then restart Claude Desktop |
354| `AADSTS7000218` request body must contain client\_assertion or client\_secret | **Allow public client flows** is set to No on the local-mode app registration, so brokered token requests are classified as confidential | Set **Allow public client flows** to **Yes** (step 1.3) |
355| Tools return a permission error or Graph `403` | A scope the tool needs is not consented on the app registration, or is excluded by an explicit `scope` list | Add the scope in both places and grant admin consent |
356| Write tools are missing or fail | The matching write scope is not listed in the entry's `scope` field, or the installed Claude Desktop version predates write support | Add the scope to the entry and consent it on the app registration (see [Grant write scopes](#grant-write-scopes)), and upgrade Claude Desktop |
357357 
358358The connector writes its sign-in and Microsoft Graph errors to its own log file in the Claude Desktop logs directory (`~/Library/Logs/Claude-3p/` on macOS, `%LOCALAPPDATA%\Claude-3p\logs\` on Windows), named `mcp-server-office365-builtin.log`. Configuration parsing and connection lifecycle messages appear in `main.log` in the same directory.
359359 
Feedback