Microsoft + ClaudeOne partner for the cloud you run and the AI you put on top of it.
Avalon Web ServicesMicrosoft · Claude · Security

Claude in Microsoft Foundry: hosted on Azure, governed by Anthropic

Choosing the Azure-hosted version of Claude in Microsoft Foundry changes exactly one thing: prompts and outputs are processed on Azure infrastructure, in your selected data zone. It does not change who is accountable. Microsoft states for both hosting options that Anthropic is the seller and operator, and acts as an independent data processor for prompts and outputs. Claude models are Non-Microsoft Products under the Product Terms, Anthropic provides whatever SLA exists, and Foundry applies no built-in content filtering to them. Only four model IDs are ever hosted on Azure, and the only data zone available anywhere is the United States.

Written by
Arif Ali Mughal
Published
Reading time
9 min

01 / 13

What does hosted on Azure actually mean for Claude?

It means the GPUs are Microsoft's. It does not mean the accountability is. Claude reached general availability in Microsoft Foundry on 29 June 2026, and the phrase hosted on Azure has been doing a great deal of unexamined work ever since.

Microsoft's own documentation is unusually direct about this, and says the same thing on two separate pages: for both hosting options, Anthropic is the seller and operator of Claude models in Microsoft Foundry, and acts as an independent data processor for prompts and outputs. Anthropic's own general availability post says the matching thing from the other side — Anthropic operates the inference and is the data processor.

So three roles are in play and they do not all belong to the same company. Microsoft is the infrastructure provider on one of the two options. Anthropic is the operator, the data processor, the seller of record and the source of whatever service level agreement exists, on both. Reading hosted on Azure as inside the Microsoft contractual boundary is the most expensive mistake available here, and an easy one to make.

02 / 13

Three roles, two companies, one row that changes

Set the two hosting options side by side and the useful information is in the rows that are identical, not the row that differs.

It matters commercially too. Claude models are classified as Non-Microsoft Products under the Product Terms, a phrase appearing on three separate Foundry pages. What that classification actually changes is never spelled out, so treat it as a prompt to read your Product Terms rather than a settled answer.

WHAT “HOSTED ON AZURE” ACTUALLY CHANGES HOSTED ON AZURE HOSTED ON ANTHROPIC Infrastructure Microsoft — your Azure region Anthropic — outside Azure Operator Anthropic Anthropic Data processor Anthropic, independent Anthropic, independent Seller of record, SLA Anthropic Anthropic One row changes between the hosting options. The other three do not: Anthropic is operator and processor either way. Only four model IDs are ever hosted on Azure: opus-5, opus-4-8, sonnet-5, haiku-4-5. Every other Claude in Foundry runs outside.
Only the top row changes. Choosing the Azure-hosted version moves the silicon into your Azure region; it does not move the operator, the data processor, the seller of record or the service level agreement, all of which stay with Anthropic on both options.

03 / 13

Only four models are ever hosted on Azure

Foundry offers Claude in two versions. Version 1 runs on Anthropic's infrastructure, outside Azure. Version 2 runs on Azure infrastructure end to end and is generally available. Not every model exists in both, and the split is narrower than the announcement coverage implies.

Model IDHostingDeployment types
claude-opus-5, claude-opus-4-8, claude-sonnet-5Azure and Anthropic, both GAGlobal Standard on both. Data Zone Standard (US) on the Azure-hosted version only.
claude-haiku-4-5Azure and Anthropic, both GAGlobal Standard only. No data zone.
claude-opus-4-7, claude-opus-4-6, claude-opus-4-5, claude-sonnet-4-6, claude-sonnet-4-5Anthropic infrastructure only, GAGlobal Standard. Processed outside Azure, potentially outside your selected Azure region.
claude-fable-5Anthropic infrastructure only, PreviewGlobal Standard. Carries a default quota of zero, so access is gated.
claude-mythos-5, claude-mythos-previewAnthropic infrastructure only, gated research previewNot listed in any deployment-type or quota table. Entra ID authentication only.

04 / 13

There is no EU data zone for Claude

This is the finding most likely to change a design, and it is a table lookup rather than an interpretation. Foundry's region matrix lists Data Zone Standard availability for Claude across four tabs. The Americas tab lists three models across eight US regions. The Europe, Asia Pacific, and Middle East and Africa tabs each read, in full, Not available.

European and Asia Pacific data zones exist as a Foundry concept; they simply carry no Claude models. Anthropic agrees from its own side: selecting Data Zone creates a US Data Zone Standard deployment, keeping inference within the United States.

  • A timeline for an EU data zone is not published. There is an open question on Microsoft's own Q&A asking for one. Until it exists, a European workload has two honest options: Global Standard with no residency guarantee, or a different model.
  • Global Standard is not a residency control. Microsoft describes it as processing in any Azure region where you deploy the model, and all Global Standard deployments of a model share one quota pool across every region.

05 / 13

Where do your Claude prompts actually go, product by product?

Four Microsoft-family products can put Claude in front of your users, and they give four different answers about where the prompt is processed. Every row below is first-party documented and was checked on 28 August 2026.

ProductWhere inference happensThe documented caveat
Microsoft Foundry, Azure-hostedAzure infrastructure, including request ingress, API services and GPU inferenceData Zone Standard is available for three models, United States only. Anthropic remains the operator and data processor.
Microsoft Foundry, Anthropic-hostedAnthropic infrastructureMicrosoft states data might be processed outside of Azure, including outside your selected Azure region.
Microsoft 365 Copilot, Researcher, Copilot Studio, Power Platform, Copilot in Microsoft 365 appsAnthropic as a Microsoft subprocessorMicrosoft states these are currently excluded from the EU Data Boundary and, where applicable, in-country processing commitments. The product list is prefaced with such as, so read it as illustrative.
Copilot Studio, non-US regions specificallyMarked cross-geo for every Claude model outside the United StatesCross-geo is defined as: might require data processing and storage outside of your organization's geographical boundaries. Admins can turn cross-region data movement on or off.
GitHub CopilotAmazon Web Services, Anthropic PBC and Google Cloud PlatformNot Azure. GitHub holds a zero data retention agreement with Anthropic for generally available features, but not for beta features such as tool search, and not for Claude Fable 5.

06 / 13

A fair word about that GitHub row

It would be easy to read that row as GitHub Copilot quietly shipping your code to Amazon and Google. Claude is not being singled out. GitHub documents hosting for every family: Gemini runs on Google Cloud, Grok on xAI, and OpenAI models are the ones partly on GitHub's Azure infrastructure. The point is that an enterprise assuming Microsoft product, therefore Azure will be wrong in more places than it expects.

Two details a security review should still capture. GitHub does not document which of the three providers hosts which Claude model, so where exactly is unavailable rather than reassuring. And the zero-retention agreement has two named exceptions — beta features, and Fable 5, for which Anthropic retains prompts and outputs to operate safety classifiers.

07 / 13

What security and governance controls do you actually get?

Fewer than the Azure branding suggests, and the gaps are documented rather than hidden. This is the section to read before a Claude deployment reaches a control document.

  • Foundry content filters do not apply. Microsoft's Claude page states it plainly: configure AI content safety during model inference, because Foundry does not provide built-in content filtering for Claude models at deployment time. Safety comes from Anthropic's own systems, on both hosting options.
  • There is no published SLA. The hosting-comparison table says, identically for both options, that Anthropic is the operator and provides any SLA. No percentage, no credit schedule, no linked document. Microsoft reserves the phrase enterprise-grade service level agreements for models it sells directly.
  • Private endpoints and customer-managed keys are not documented for partner models. They are absent from every Claude page, and the private-link limitations section never addresses Marketplace-sold models. Absence of documentation is not a denial — but it is not something to write into a control matrix either.
  • Microsoft Entra ID authentication is supported, alongside API keys, and the Mythos models support Entra ID only. This is the one part of the Azure-native governance story that is unambiguously documented.
  • Zero data retention is asserted but not documented. The announcement blog says it is available for high-sensitivity workloads. The only mention across Microsoft's Claude documentation is a troubleshooting row explaining that ZDR blocks certain models and that Anthropic manages the setting independently, so Microsoft cannot change it for you. Anthropic's retention page names Foundry in scope, then omits it from both the covered and not-covered lists. Get this in writing before relying on it.
  • HIPAA readiness is not available on Claude Platform on AWS or Microsoft Foundry, per Anthropic's documentation.

08 / 13

The admin controls, and the date that inverts them

The tenant-level story is genuinely well documented, and it has a wrinkle that catches people out.

The default is on for most commercial-cloud customers, excluding the EU, EFTA and the UK, where the setting appears but defaults to no users. Organisations there that previously opted in under Anthropic's separate commercial terms must opt in again — the toggle was reset to off, and the older independent-processor setting was decommissioned on 1 May 2026.

  • The 25 March 2026 cutoff inverts the default for new tenants. A separate, narrower setting introduced on 3 April 2026 — Copilot in Microsoft 365 apps with Anthropic models — is on by default for EU, EFTA and UK tenants created after 25 March 2026. Tenants that existed before that date are told to check the Message Center. There is no documented default for them.
  • It is a different switch. Microsoft is explicit that this setting is separate from the global subprocessor toggle and that changing it does not modify the global configuration. Two settings, two defaults, one easily conflated audit answer.
  • Government cloud is a hard boundary. Non-federal GCC customers gained an opt-in on 22 July 2026, disabled by default, and Microsoft notes that enabling it processes customer data outside its FedRAMP-authorized US Government cloud. For federal GCC, GCC High and DoD, the option does not appear at all.
  • Copilot Studio needs two gates, not one. External models must be turned on in the Power Platform admin center for the environment or environment group, and the provider must be allowed in the Microsoft 365 admin center.
  • Word has not shipped. The Microsoft 365 apps setting covers Excel and PowerPoint; the page, revised on 18 August 2026, still says Anthropic support for Word will be added in summer 2026.

09 / 13

What changes the moment you enable a preview model

This is the sharpest line in the whole subject, and it is a legal one rather than a technical one. For generally available Anthropic models, Anthropic has onboarded as a Microsoft subprocessor, and Microsoft's Product Terms and Data Protection Addendum apply. For models labelled Preview models with Data Retention — currently Claude Fable 5 and Claude Mythos 5 — Anthropic acts as an independent data processor, not a Microsoft subprocessor, and the data is expressly not subject to your Microsoft Customer Agreement.

Read the retention terms carefully; they are routinely flattened into a schedule they are not. Every period is an upper bound, and the two longer tiers apply only if Anthropic's trust and safety classifiers flag a potential Usage Policy violation.

What is retainedFor how longUnder what condition
Most inputs and outputsUp to 30 days before deletionStandard behaviour for these models. Retention is by Anthropic, not Microsoft.
Content, meaning inputs and outputsUp to two yearsOnly where trust and safety classifiers identify a potential violation of Anthropic's Usage Policy.
Trust and safety classification scoresUp to seven yearsSame trigger. Note this tier covers the scores, not the content itself.
Training useNot without your express permissionThe carve-out is part of the sentence. It is not an unconditional commitment never to train.

10 / 13

How the money flows, and why it might matter more than you think

Claude in Foundry bills through a Claude Consumption Unit, a unit of measure used solely for invoicing. Anthropic meters your tokens, prices them at its own rates, applies any negotiated discount, converts the result to CCU, and reports it hourly to Azure Marketplace, where it lands as one line on your Azure invoice.

The commercially interesting part: the CCU meter is MACC-eligible, so Claude spend decrements a Microsoft Azure Consumption Commitment exactly as other Marketplace consumption does — and Microsoft adds that CCU billed by other cloud providers does not. If you are sitting on an unspent Azure commitment, that is a real argument for the Foundry path over calling Anthropic directly, and the one place where Non-Microsoft Product works in your favour. Two footnotes: Microsoft never prints the CCU price, deferring to the Marketplace offer, while Anthropic publishes it as one cent per CCU; and free trial, student, credit-based, South Korean Enterprise and CSP subscriptions cannot use Claude at all.

11 / 13

Where the documentation disagrees with itself

Naming the contradictions is more useful than picking a winner, because these are the sentences a well-prepared architect gets caught on. All four were checked on 28 August 2026.

SubjectThe disagreementHow to read it
Content filteringThe Foundry deployments overview says Serverless API deployments — a category defined to include select models from partners and community — have built-in and customizable content filtering. The Claude page says Foundry does not provide built-in content filtering for Claude models at deployment time.The Claude page is newer and more specific, so plan for no built-in filter. But this one is material enough to confirm with your account team before it reaches a control document.
Support routing against SLA ownershipThe hosting-comparison page routes all Claude support questions to Microsoft Support. The Foundry models overview says partner-model support and maintenance is managed by the respective providers, and the SLA is Anthropic's.You raise the ticket with Microsoft; the remedy, if any, is Anthropic's. Establish the escalation path before you need it.
Word supportThe Microsoft 365 apps page, revised 18 August 2026, says Anthropic support for Word will be added in summer 2026. An older overview page lists Word among the apps Copilot Cowork acts across using Anthropic models.These are arguably different surfaces — acting on a Word file, versus Copilot inside Word — but the documentation never draws that distinction. The older page is the stale one.
One model, three lifecycle labelsOn the same day, Claude Fable 5 is generally available in GitHub Copilot, Preview in Microsoft Foundry, and Preview and off by default in Copilot Cowork.Model lifecycle status is per product, not per model. Never carry a status claim across a product boundary.

12 / 13

What I would do with this

Author-proposed, not vendor guidance, and deliberately conservative — this is a young surface and the documentation is still moving underneath it.

  • Write the accountability split into your vendor record now. Anthropic is the operator, data processor, seller of record and SLA provider on both hosting options. If your third-party register says Microsoft, it is wrong, and it is wrong in the direction an auditor will notice.
  • Do not put European personal data through Claude in Foundry expecting residency. There is no EU data zone, and Global Standard is not a residency control. If residency is a requirement, this is a blocker, not a configuration task.
  • Assume no content filter and build your own. Configure content safety at inference time, as Microsoft's own page instructs, rather than assuming the platform default you get with first-party models.
  • Keep preview models off unless someone has read Anthropic's terms. Fable 5 and Mythos 5 move you outside your Microsoft Customer Agreement entirely. That may be an acceptable trade; it should never be an accidental one.
  • Check your MACC position before choosing a path. If you hold an unspent Azure consumption commitment, the Foundry route converts Claude spend into commitment drawdown. That is a genuine, documented advantage and it is easy to leave on the table.
  • Date-stamp whatever you write. Four of the pages behind this article were revised in the six weeks before publication. Record the date you checked, not just the finding.

13 / 13

When is this worth bringing in outside help?

Not for a proof of concept. Deploying a Claude model in Foundry is a Marketplace subscription and an endpoint; you will learn more doing it than reading about it.

It is worth help at three points. The first is the vendor and regulatory record — if Claude has to appear in a third-party risk register, a data protection impact assessment or an examiner's file, the accountability split above has to be right the first time. The second is a residency constraint, especially where someone has already promised that Azure hosting solves it. The third is a multi-surface estate, where Foundry, Microsoft 365 Copilot, Copilot Studio and GitHub Copilot each give a different answer and nobody owns the whole picture.

Disclosure: Avalon Web Services sells Microsoft and AI integration work, including the Copilot pilot package linked below, so read this as an interested opinion. The three tests are the honest ones. If none of them describes you, the documentation cited here is enough to do it yourself.

Primary sources

Want us to run this for you?

Start here

Tell us what'skeeping you upat night.

Most engagements start with a Cloud Health Check — one week, full audit, top-10 findings, 90-day roadmap. Many turn into a longer engagement; either way, you walk away with a prioritized plan you own.