What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Claude connects to Salesforce, Slack, and Microsoft 365 through different products and permission models—not one uniform integration. The available vendor documentation does not establish that Claude bypassed any organization’s security review. But it does identify controls that security teams should verify, especially Microsoft 365’s tenant-wide SharePoint search permission and limitations involving some Conditional Access policies. Inventory each connection separately, confirm who authorized it and what it can do, and test the controls in your own environment.

How the three connections differ

Platform What the vendor material describes Approval or availability detail
Microsoft 365 Anthropic-hosted, user-delegated connector for Outlook, SharePoint, OneDrive, and Teams; read permissions are the default, with optional write tools. A Microsoft Entra Global Administrator must grant tenant consent; Team and Enterprise plans also require an organization owner to enable the connector. Anthropic security guide and setup guide.
Slack Slack app installation and scope controls, followed by a user connecting a Claude account. Slack announced a transition from the Claude app to Claude Tag. Members permitted to install apps or Enterprise organization roles can install it. The reviewed help page said the transition would start August 3, 2026; current Claude Tag details are not established there. Slack Help Center.
Salesforce Salesforce announced Claudeforce, including Salesforce in Claude and Claude availability in Salesforce offerings. Salesforce described Salesforce in Claude as available to select pilot customers, with open beta expected in September 2026. The announcement does not establish whether that beta occurred or document detailed connector scopes. Salesforce announcement, August 26, 2026.

Microsoft 365: check delegated access, search scope, and Conditional Access

What can Claude see?

Anthropic says the connector uses a person’s delegated Microsoft 365 permissions; it does not give that person access to information they cannot already view. Files and messages remain in the Microsoft 365 tenant and are retrieved on demand for active queries. Anthropic says file content is not cached, but content from tool-call results included in saved Claude chats is retained as chat content—so “not cached” does not mean “nothing is retained.” Delegated access follows Microsoft 365 DLP policies. Shared mailboxes are available only when the user has delegated access to them, and that access is read-only. See the Microsoft 365 connector security guide.

What does SharePoint search require?

SharePoint search requires the tenant-wide Sites.Read.All permission, according to Anthropic. Site-specific *.Selected permissioning is not supported because the connector’s search is tenant-wide. That does not mean a user can read every site: the connector is described as mirroring the user’s existing access. It does mean administrators should assess the breadth of the application permission separately from the user-level access boundary, and verify the tenant’s consent and configuration before enabling search.

Can Claude send messages or change files?

Write tools are not enabled by default. Anthropic’s setup guide says they require consent to updated permissions and an organization-level enablement step. If enabled, the tools may allow actions such as sending email, managing calendar events, creating or updating files, and sending Teams messages. Decide whether those actions are needed; grant only the appropriate permissions and establish who can enable or revoke them. Consult Anthropic’s setup instructions for the organization’s current setup flow.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Will Conditional Access still enforce network rules?

Do not assume that existing location or network restrictions will work unchanged. Anthropic says Entra evaluates the user’s connection, but later requests are made from Anthropic’s server IP range, 160.79.104.0/21. Its guide says location/network restrictions and sign-in frequency policies are unsupported as expected in this server-side flow. Group-based access and MFA are supported with the documented configuration. Device compliance is evaluated against the device recorded at connection, and later activity can fail if that recorded device is noncompliant. Test the exact policies in your tenant before rollout rather than treating a successful sign-in as proof that subsequent requests follow the same network boundary.

How can access be revoked?

Anthropic says an administrator can disable the connector in Claude organization settings, while specific capabilities can be revoked in Entra, including SharePoint, email, Teams chat, Teams message writing, and OneDrive. Users or administrators can revoke access. Refresh tokens expire after 90 days of inactivity by default, according to the guide. Assign an owner for both organization-level shutdown and permission-level revocation so those are actionable procedures rather than undocumented options.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Slack: review app installation and scopes, then verify Claude Tag

Slack’s help page says members allowed to install apps can install the Claude app; Enterprise organization roles can install it for the organization and choose workspaces. Administrators can review scopes and allow access for everyone, selected members or groups, or no one. Users then connect a Claude account. These are Slack’s documented controls for the Claude app; do not assume they describe the current Claude Tag implementation.

The same page said Claude Tag would replace the current Claude app starting August 3, 2026. That date has passed, but the reviewed page does not provide enough Claude Tag-specific technical detail to establish its present scopes, data handling, or permission model. Check the current app listing and granted scopes in Slack administration, confirm which workspaces and people can use it, and assess the current product documentation before relying on controls described for the predecessor app. Slack’s Claude help page.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Thetis Nano-C for Business - USB C FIDO2 Security Key L1 MFA & Passkey Access for School ERP, Employee Online Account, Compatible with Coinbase Google Workspace Apple ID Window Salesfore - 2 Pack
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • USB TYPE C Connectivity & DONGLE Design: Designed for PCs, Macs, laptops, iPhones, and Android devices that utilize a USB-C port. Plug and stay, or carry it on a keychain. (Item Size: 0.73 x 0.60 x 0.30 inches)
  • Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC functionality is not supported.

Salesforce: treat Claudeforce details as a dated announcement

Salesforce’s August 26, 2026 announcement described Claudeforce as including Salesforce in Claude, a plugin with 37 prebuilt sales skills for tasks such as meeting preparation, deal-health and pipeline review, and pipeline updates. Salesforce said setup uses a single admin connection with centrally managed authentication and permissions, and that actions route through Salesforce so business rules are enforced. These are Salesforce’s claims; the announcement does not spell out detailed scopes or provide enough information to independently assess the implementation.

The announcement said Salesforce in Claude was available to select pilot customers and that open beta was expected in September 2026. It does not confirm whether the beta began, what availability is now, or what the current permissions are. Salesforce also described Claude in Agentforce and other Salesforce offerings, including Claude via Amazon Bedrock within the Salesforce Trust Boundary. Confirm which product path your organization uses and obtain its current configuration and permission details; do not treat the announcement as a universal description of every Salesforce–Claude deployment. Read Salesforce’s announcement.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Audit coverage is not the same as app-level visibility

Anthropic’s Compliance API documentation says Claude Enterprise organizations can retrieve Activity Feed events and access enterprise directories, effective settings, chats, files, projects, and sessions, including Claude for Microsoft 365. Anthropic describes the API as supporting audit, content retrieval or deletion, and downstream tooling. Its documentation distinguishes retrospective Compliance API retrieval from beta inference hooks, which can deny governed prompts inline. The presence of these capabilities does not establish that every third-party app action or every relevant event is captured identically. Validate what your own audit pipeline receives and retain the logs needed for the controls you require.

Anthropic’s integrations page names SentinelOne, Snyk, and Sola Security integrations based on the Compliance API. These are options to investigate for governance workflows, not evidence that a particular deployment meets your audit requirements. See Anthropic’s Compliance API documentation and its guide to Compliance API integrations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Swissbit iShield Key 2 Pro USB-C Multi-Application Security Key with NFC – FIDO Certified, Passkey (FIDO2), PIV Smart Card & OTP Authentication, Phishing-Resistant Security for Enterprise
  • MULTI-APPLICATION SECURITY KEY FOR ENTERPRISE USE: Supports FIDO2 passkeys, U2F, Smart Card (PIV), and OTP for flexible authentication across enterprise environments.
  • PHISHING-RESISTANT AUTHENTICATION: Enables passwordless login with secure credential storage and PIN-based user verification.
  • COMPATIBLE WITH ENTERPRISE SYSTEMS: Works with FIDO2, WebAuthn, U2F, PIV, and OTP across enterprise, cloud, and identity infrastructure.
  • DRIVERLESS FIDO2 AUTHENTICATION: FIDO2 works natively with modern browsers and platforms. Additional software may be required for PIV or OTP
  • USB AND NFC CONNECTIVITY: Supports authentication via USB-C and NFC. No batteries or drivers required for FIDO2.

Security review checklist for rollout

  1. Inventory the connections. Identify connected Claude apps, the users and workspaces using them, the Salesforce product path in use, and the responsible administrators.
  2. Inspect consent and scopes. Review granted OAuth or app permissions and tenant-level consent; for Microsoft 365, explicitly assess the need and impact of tenant-wide Sites.Read.All.
  3. Set read and write boundaries. Decide whether read access is sufficient. If enabling Microsoft 365 write tools, document which actions are permitted and who approves the additional permissions and organization setting.
  4. Test identity and data controls. Validate Microsoft Conditional Access behavior for the actual tenant policies, including location, network, sign-in frequency, MFA, groups, and device compliance. Check DLP behavior and the relevant app’s current permissions separately for Slack and Salesforce.
  5. Limit access and assign revocation ownership. Use the available group, member, workspace, and organization controls; name the people responsible for disabling an integration and revoking its permissions.
  6. Verify audit evidence. Confirm which events, content, and sessions appear in your compliance tools and whether that coverage is sufficient for your policy. Do not infer third-party app coverage from the existence of an API alone.
  7. Recheck changed products. Validate current Slack Claude Tag behavior and Salesforce availability and scopes against current vendor documentation before approving or expanding use.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.