Claude Cowork and Outlook: What Connects, What Sends
Cowork has no Outlook connector of its own. It uses Claude’s Microsoft 365 connector, the same one chat uses, and that connector is the whole story: what it reaches, who has to approve it, and why a scheduled Cowork task still cannot email your team.
There are three separate Microsoft things with Claude’s name on them, and mixing them up is the usual source of confusion. The Microsoft 365 connector is what Cowork uses. The Claude for Outlook add-in runs inside Outlook and never sends. Claude for Microsoft 365 is the Office-app integration. This page is about the first one.
The blocker that stops most people before they start
Anthropic states it plainly, and it is the first thing to check:
The Microsoft 365 connector requires a Microsoft Entra tenant tied to a Microsoft Business plan. Personal Microsoft accounts (such as @outlook.com or @hotmail.com addresses) can’t be used to connect.
So a personal Outlook address cannot be connected to Cowork at all, on any plan. This is not a permissions setting you can talk your way past. If your Outlook is personal, the connector is closed to you and the Gmail side of Claude is the only mail Cowork will reach.
Two gates, and a third if you want it to send
The connector itself is available on every Claude plan, Free through Enterprise. Cowork is what needs a paid plan. Getting the connector live takes:
- A Microsoft Entra Global Administrator grants a one-time consent for the tenant. Until that happens nobody in the tenant can connect. They can do it inside Claude’s own connect flow by ticking the organization-wide box, or manually in Entra by adding two service principals,
M365 MCP Client for ClaudeandM365 MCP Server for Claude. - On Team and Enterprise, a Claude owner enables the connector under Organization settings then Connectors. On Free, Pro and Max this step does not exist.
- For sending, an admin enables write tools, which needs a second Entra consent to an updated permission set. Anthropic notes that tenants which connected before write tools launched have them blocked by default.
Read and search work identically whether or not write tools are on. Sending, calendar writes and file writes are the part behind gate three.
What Cowork can actually do on Outlook
With write tools enabled, the connector exposes a genuinely wide set of Outlook tools:
| Area | What Cowork gets |
|---|---|
| Mail, read | Search with sender and date filters, read messages by reference |
| Mail, send | Send, forward, send an existing draft |
| Drafts | Create, reply, reply-all, update, delete |
| Organising | Trash and untrash threads, batch delete, categories on a message or a whole thread |
| Mailbox settings | Create and delete inbox rules, set the automatic-reply message |
| Calendar | Create, update, delete events, respond to invitations, find availability |
| Files | Upload, update, create folders, rename, move, copy, delete in SharePoint and OneDrive |
| Teams | Search chat messages, and nothing else |
Two rows deserve attention. Inbox rules and the out-of-office message are genuinely writable through outlook_create_filter and outlook_set_vacation, which surprises people who assume Claude only drafts. And Teams stays read-only even with write tools switched on, so Cowork can read Teams chat and cannot post to it.
The fact that decides whether Cowork can work unattended
This is the one that matters most for Cowork specifically, because Cowork’s whole appeal is handing off a job and walking away. Anthropic’s security guide notes:
“Always allow” is not supported for
outlook_send_email,outlook_forward_mail,outlook_send_draft,outlook_create_event, oroutlook_update_event.
You cannot pre-approve sending. Every outbound message and every new calendar event waits for a human to click, by design, and there is no setting that changes it. So a /scheduled Cowork task can research all night, build the deck, write the mail and then stop at the approval it cannot give itself.
That is a sharper limit than “no triggers,” and it is easy to miss when you are planning around Cowork’s scheduler.
Three more constraints worth pricing in before you build on this:
- Attachments are refused everywhere. Sending, forwarding and drafting all reject messages with attachments. The deck Cowork just built cannot be attached to the mail Cowork just wrote.
- Sent mail is labelled. Emails Claude sends carry an attribution header identifying them as agent-initiated. File and calendar writes are not tagged.
- Shared mailboxes are read-only. You can search a shared mailbox you have delegate access to through
Mail.Read.Shared, but you cannot send from it.
One thing for the admins
If your tenant uses Conditional Access, location and network policies do not work here. Anthropic is direct about why: every request after the initial sign-in comes from their servers, in the range 160.79.104.0/21, rather than from the member’s device or network. A policy that limits sign-ins to your office network or VPN blocks the connector for everyone. Group-based policies and MFA are supported; device compliance is supported with the caveat that it is checked against the device recorded when the member last connected, not the one in use now.
Where this leaves an Outlook workflow
Cowork on Outlook is excellent at reading. Search the mailbox, pull the thread, reconcile it against files in SharePoint, build the summary. It is good at organising too, since categories, rules and trashing are all one-way actions that do not need the send approval.
Where it stops is the last step of anything outbound, and the reason is stacked: a personal address cannot connect, two admins stand between you and the connector, sending cannot be pre-approved, attachments are refused, and nothing starts on its own.
Both ChatGPT Scheduled Tasks and Claude Cowork can do unattended work on a timer. Neither ordinary scheduler is a general webhook or business-app event listener. ChatGPT Workspace Agents accept API triggers, but only after an upstream service notices the event.
Outlook that finishes the job
Carly connects Outlook and Gmail alike, without an Entra admin in the loop, and personal addresses are as welcome as work ones. It sends real mail with attachments from the address that received the thread, so the deck it built goes out attached to the message it wrote.
The bigger difference is what starts the work. Each agent has its own name, email address and memory, so people write to it directly and it acts when the message lands rather than when you next open a tab. An enquiry at 11pm gets a real answer at 11pm, the follow-up goes on the calendar, and the record updates itself. It holds several mailboxes at once, each authorized separately, so a work tenant and a personal address both stay connected instead of one locking the other out.
Around the mail sit 260+ native integrations plus your own API key for anything else with an API. AI agents start at $35 a month. Connect your Outlook at carlyassistant.com.
FAQ
Can I connect a personal Outlook.com account to Claude Cowork?
No. Anthropic requires a Microsoft Entra tenant on a Microsoft Business plan, and states that personal accounts such as @outlook.com and @hotmail.com cannot be used to connect.
Does Claude Cowork need an admin to reach Outlook?
Yes. A Microsoft Entra Global Administrator must grant a one-time consent for the tenant, and on Team and Enterprise plans a Claude owner must also enable the connector for the organization.
Can a scheduled Cowork task send Outlook email?
No. Anthropic does not offer “Always allow” for the send, forward, send-draft or calendar-create tools, so every one of those actions waits for a person to approve it and an unattended run stops there.
Can Claude Cowork post to Microsoft Teams?
No. Teams stays read-only even when write tools are enabled, so Cowork can search Teams chat messages but cannot send one.
Can Claude Cowork send an attachment from Outlook?
No. Attachments are not supported in any write tool, and sending, forwarding and drafting all reject messages that carry one.
Can Claude Cowork send from a shared mailbox?
No. Shared mailbox access is read-only through the Mail.Read.Shared permission, so you can search a delegated mailbox but not send from it.
More: Claude Cowork connectors · How to connect multiple Outlook accounts to Claude Cowork · Can Claude Cowork send emails · Claude for Outlook · Connect multiple email accounts to Claude Cowork
Ready to automate your busywork?
Carly schedules, researches, and briefs you—so you can focus on what matters.
See what people say
"Before Carly, I relied on a Calendly link, but the whole process felt impersonal and not very professional. Carly changed that by handling all the back-and-forth, so I'm no longer stuck in endless email threads trying to line up schedules.
Now Carly reaches out to candidates, shares my real-time availability, lets them pick a slot, then sends a Zoom link and drops it straight into my calendar. She sends reminders to both of us before each call, which has significantly reduced no-shows and last-minute confusion.
On top of scheduling, Carly acts like a full executive assistant, sending me my schedule the night before so I can prepare for each call. It reminds me of the old x.ai assistant, but Carly is noticeably smarter, faster, and better suited to my healthcare recruitment business."


