TLDR: You can set up Claude single sign-on (SSO) with Microsoft Entra ID in about 10 minutes on a paid Claude Team or Enterprise plan. The process has three parts: verify your company domain in Claude, connect Claude to Entra through Claude’s guided setup, and control access by assigning users or groups in Entra. Once enforced, every Claude login runs through Entra, your existing MFA/Conditional Access applies automatically, and removing someone in Entra removes their Claude access.

Why Claude SSO matters (the shadow account problem)

Here is how Claude usually gets into a company. Not through IT. Someone signs up on their own with a personal email and starts using it for real work.

To get good answers, they feed it real data. Customer lists. Contracts. The financial model. The product roadmap. All of it goes into a personal account that nobody approved and nobody can see. Now multiply that by half your team.

Then someone leaves. Their Claude account walks out with them, along with every conversation and every file they uploaded, sitting in an account your company never controlled and cannot shut off.

That is the gap single sign-on closes. When Claude sits behind Microsoft Entra, company data lives in accounts you control, and the day someone leaves, their access leaves with them. This is not about blocking Claude. It is about governing it.

Ungoverned vs. governed Claude access

The difference between an unmanaged Claude footprint and one behind Entra SSO comes down to five areas.

Access areaUngoverned (no SSO)Governed (paid plan + Entra SSO)
IdentityScattered logins on personal and work emailOne identity, sourced from Entra
MFA and accessInconsistent, often optional or offInherits your tenant MFA and policies
OffboardingManual, accounts linger after people leaveInstant: leave the group, lose access
Shadow accountsAnyone signs up on the company domainDomain locked, no rogue accounts
OversightNo central view of who has accessCentral control and an audit trail

What you need before you start

Before you configure Claude SSO with Entra, confirm the following:

  • A paid Claude plan. SSO requires Claude Team or Claude Enterprise. It is not available on personal or Pro accounts.
  • Owner or Primary Owner access in Claude, so you can reach the organization settings.
  • Access to your DNS provider, so you can add a verification record.
  • Admin rights in Microsoft Entra (Global Administrator or Application Administrator).
  • For automated provisioning (Enterprise): an Entra ID P1 or P2 license is required for SCIM. Team plans use group assignment and Just-in-Time provisioning instead.

How to set up Claude SSO with Microsoft Entra ID

The whole flow runs through a guided wizard inside Claude that gives you the exact values to paste into Entra. Keep your Claude admin settings open in one tab and the Entra admin center in another, and move between them.

Step 1: Verify your domain

  1. In Claude, go to admin settings, then Organization and access (claude.ai/admin-settings/organization).
  2. In the Domains section, click Add or edit domains, enter your company domain, add it, and save.
  3. Click Verify. Claude generates a DNS TXT record.
  4. Add that TXT record at your DNS provider and save.
  5. Wait for DNS to propagate. This usually takes about 10 minutes but can take up to 24 hours. Refresh until you see the green Verified badge.

Verifying your domain on its own does not lock anyone out. It simply proves you own the domain so you can configure SSO for it.

Step 2: Connect Claude to Microsoft Entra

  1. In Claude, under Organization and access, find the Authentication section and click Setup SSO. This launches the guided setup. Leave it open as your reference.
  2. In the Microsoft Entra admin center, go to Enterprise applications, then New application. Search the gallery for “Claude” and select it, or choose Create your own application, name it Claude, and pick Integrate any other application you don’t find in the gallery.
  3. Open the new Claude app, click Single sign-on, and follow the values Claude’s setup provides: an Identifier and a Reply URL to paste into Entra, with a sign-on URL of https://claude.ai/login.
  4. Confirm Entra is sending the user’s email as the user.mail attribute.
  5. Download the metadata file from Entra and upload it back into Claude’s setup. That file fills in the rest of the connection automatically.

Step 3: Control who can access Claude

This is the access lever most admins are after.

  1. In your Claude app in Entra, go to Users and groups.
  2. Assign a security group, for example “Claude Users.” Everyone in that group can sign in to Claude.
  3. To grant access, add a person to the group. To revoke access, remove them. This works on both Team and Enterprise.

On Enterprise, you can go further with automated provisioning (SCIM), which removes a user from Claude the moment they leave the group. On Team, you rely on group assignment. Either way, removing a user in Entra cuts their Claude access.

Step 4: Test, then enforce SSO

Before enforcing SSO for everyone, test it with a non-admin account. Log out, choose Continue with SSO, and confirm you land in your organization’s workspace. Once that works, return to the Authentication section in Claude and turn on Require SSO for Claude. Now every login runs through Entra and the password sign-in is closed.

While you are there, turn on Restrict organization creation. This prevents employees from spinning up personal Claude accounts on your verified domain, which is the single biggest fix for shadow AI exposu

Team vs Enterprise: which provisioning option do you need?

Both plans support SSO, but they differ on user lifecycle automation:

  • Claude Team uses Invite Only or Just-in-Time (JIT) provisioning, combined with group assignment in Entra. Access is controlled, but deprovisioning is driven by removing people from the group.
  • Claude Enterprise adds SCIM provisioning, which automatically creates and deactivates users in Claude based on Entra group membership.

Find the Shadow AI Before You Govern It

You cannot govern what you cannot see. Before you decide which AI tools to standardize on, you need visibility into what your users are already running.

If you manage Microsoft 365 environments, CloudCapsule runs a rapid assessment against your tenant for a range of security risks, each with clear remediation guidance. The recent Shadow AI report analyzes shadow IT across browsers and workstations, surfacing exactly which users are leveraging tools like Claude and what individual AI tools they have in use. That is the starting point for deciding what to govern, what to adopt, and what to block.