On June 18, Anthropic introduced enterprise-managed authorization for MCP connectors — a way for admins to provision connectors for an entire organization through their identity provider, starting with Okta. Users get access automatically the first time they open Claude, with no individual sign-in steps. Here is what changed and what it means for your Cowork setup.
Connectors That Set Themselves Up
Until now, switching on a connector took two steps: an admin enabled it for the organization, then every user authorized it individually. Enterprise-managed authorization removes that second step. An admin authorizes a connector once, users inherit access through the identity-provider groups and roles they already have, and the connector is simply there the first time someone opens Claude. Anthropic calls the result zero-touch connector setup for the end user.
Access stays consistent across Claude chat, Claude Code, and Cowork, so the connectors set up for your organization are available to your Cowork agents without extra configuration. It is the first implementation of the Enterprise-Managed Authorization extension to the Model Context Protocol — an open standard — so any connector, including custom ones your team builds, can support it.
Why It Matters for Cowork Teams
Cowork leans on connectors — they give Claude the context it needs from the tools your team already uses. For Team and Enterprise customers, enterprise-managed auth folds connector access into the same identity workflow that governs the rest of your stack: provision once, scope by group, and manage revocation through the identity provider.
Because access is checked against the identity provider, admins can shorten access-token lifetimes without hurting productivity — so when someone is deprovisioned, their connector access expires quickly instead of lingering on an old token. Admins can also require that a connector only ever connect through the identity provider, which keeps work and personal accounts cleanly separated.
Who Is On Board at Launch
Okta is the first supported identity provider, with more coming soon. On the connector side, Asana, Atlassian, Canva, Figma, Granola, Linear, and Supabase support enterprise-managed auth at launch, with Slack coming soon. Early adopters rolling it out across their teams include HubSpot, Ramp, and Webflow. The feature is available today in beta for customers on the Claude Team and Enterprise plans.
Tip of the Week: Stop Authorizing Connectors One by One
If your team is on Claude Team or Enterprise, you no longer have to walk every person through a stack of sign-in screens to get them connected in Cowork. Let your identity provider do the work.
❌ Weak
Every new hire manually authorizes each connector before they can use it in Cowork. ✅ Strong
Admin enables enterprise-managed auth and maps connectors to Okta groups.
New hire logs in once — approved connectors like Asana and Linear are already there.
Access is scoped by identity-provider role and revoked automatically at offboarding. The rule of thumb: let the identity provider you already trust manage connector access — it is less setup for users and tighter control for admins.
Worth Reading This Week
- → Centrally manage authorization for MCP connectors — Claude — The announcement, covering how zero-touch provisioning works and the identity and connector partners supporting it at launch.
- → Authorize MCP connectors for your entire organization — Claude Help Center — The admin setup guide for enabling enterprise-managed authorization on Team and Enterprise plans.
- → Enterprise-Managed Authorization for MCP — Model Context Protocol — The open extension to the MCP authorization spec that any identity or connector provider can implement.
Enterprise-managed auth will not change much for solo Cowork users yet, but for teams it removes one of the last friction points in getting Claude wired into real work. Expect more identity providers and connectors to follow.
Until next time.
— The ClaudeCowork.com team