Enterprise deployment options
Compare Claude for Teams and Enterprise, the Console, Amazon Bedrock, Claude Platform on AWS, Vertex AI and Microsoft Foundry for an organisation-wide Claude Code rollout.
When an organisation adopts Claude Code, the first real decision is where inference runs and who sends you the bill. You can buy directly from Anthropic or run through a cloud provider you already have a contract with. This page compares the options and covers the networking and rollout habits that apply whichever you pick.
For most organisations the answer is Claude for Teams or Enterprise. One subscription covers Claude Code and Claude on the web, billing is central and there is no infrastructure to run. Teams is self-service with SSO, admin tools and server-managed settings, and suits smaller groups getting going quickly. Enterprise adds domain capture, role-based permissions and the compliance API for larger, more regulated organisations.
The cloud-provider routes make sense when procurement, data residency or existing commitments push you there. They change where inference runs; if you want cloud sessions to run on your own compute, that is a separate topic covered by self-hosted environments.
Side by side
| Teams / Enterprise | Anthropic Console | Amazon Bedrock | Claude Platform on AWS | Google Vertex AI | Microsoft Foundry | |
|---|---|---|---|---|---|---|
| Good for | Most organisations | Individual developers, API-first teams | AWS-native estates | AWS Marketplace billing with Claude API features | GCP-native estates | Azure-native estates |
| Billing | Per seat (Teams, with pay-as-you-go available) or by contract (Enterprise) | Pay as you go | Pay as you go via AWS | Pay as you go via AWS Marketplace | Pay as you go via GCP | Pay as you go via Azure |
| Regions | Anthropic-supported countries | Anthropic-supported countries | Several AWS regions | Several AWS regions | Several GCP regions | Several Azure regions |
| Prompt caching | On by default | On by default | On by default | On by default | On by default | On by default |
| Sign-in | claude.ai SSO or email | API key, or Console sign-in without a key | API key or AWS credentials | API key or AWS credentials | GCP credentials | API key or Microsoft Entra ID |
| Cost reporting | Usage dashboard | Usage dashboard | AWS Cost Explorer | AWS Cost Explorer | GCP Billing | Azure Cost Management |
| Includes Claude on the web | Yes | No | No | No | No | No |
| Governance | Team management, SSO, usage monitoring | None | IAM, CloudTrail | IAM, CloudTrail | IAM roles, Cloud Audit Logs | RBAC, Azure Monitor |
Some features only exist with a claude.ai account, so the cloud routes lose them. The feature availability page has the full matrix.
Setup guides
- Teams or Enterprise, and the Console: authentication
- Claude apps gateway: a self-hosted gateway that puts your IdP sign-in in front of Bedrock, Claude Platform on AWS, Vertex AI, Foundry or the Anthropic API
- Amazon Bedrock
- Claude Platform on AWS
- Google Vertex AI
- Microsoft Foundry
For Bedrock and Vertex AI there is also a guided route: run claude, choose 3rd-party platform at the login prompt, and a wizard walks through the configuration.
Proxies and gateways
Most teams can talk to their provider directly. Two kinds of intermediary are common, and they can be combined:
| Corporate proxy | LLM gateway | |
|---|---|---|
| What it is | An HTTP/HTTPS proxy all outbound traffic must pass through | A service between Claude Code and the model provider that handles auth and routing |
| Why | Security monitoring, compliance, network policy | Central usage tracking, budgets or rate limits, central credentials |
| Configure with | HTTPS_PROXY or HTTP_PROXY | ANTHROPIC_BASE_URL, ANTHROPIC_BEDROCK_BASE_URL, ANTHROPIC_AWS_BASE_URL, ANTHROPIC_VERTEX_BASE_URL or ANTHROPIC_FOUNDRY_BASE_URL |
| Read more | Network configuration | LLM gateway, connecting to a gateway |
Run /status in a session to see which provider, base URL and proxy it is actually using. It is the first thing I check when someone says "it works on my machine".
Note: If you use customer-managed encryption keys and send Claude Code through a gateway or custom
ANTHROPIC_BASE_URL, CMEK does not cover Claude Code's operational telemetry on those sessions. To switch that telemetry off for everyone, deliverDISABLE_TELEMETRYthrough managed settings.
Rollout habits that work
Write things down for Claude. Claude Code is only as good as its understanding of your codebase. CLAUDE.md files can live at organisation, repository and directory level; the memory page explains where each goes and how to deploy an organisation-wide one.
Make installation one step. If your developer environment is at all bespoke, a one-command or one-click install (a script, an image, a package in your internal repository) does more for adoption than any amount of training. A dev container is one good option.
Start small. Encourage people to begin with questions about the codebase and small bug fixes, to ask for a plan first and to push back when it goes off course. Autonomy comes once they have a feel for it.
Pin models on cloud providers. On Bedrock, Vertex AI, Foundry and Claude Platform on AWS, set ANTHROPIC_DEFAULT_FABLE_MODEL, ANTHROPIC_DEFAULT_OPUS_MODEL, ANTHROPIC_DEFAULT_SONNET_MODEL and ANTHROPIC_DEFAULT_HAIKU_MODEL to specific model IDs. Otherwise aliases resolve to Claude Code's built-in default for that provider, which can trail the newest release or point at a model your account has not enabled yet. Pinning lets you choose when people move. See model configuration.
Set security policy centrally. Managed permissions decide what Claude Code may and may not do, and local configuration cannot override them. See security and managed settings. To lock a machine to particular providers, use allowedProviders (v2.1.285+): ["bedrock"] permits only Bedrock, and a Bedrock fleet that also uses the Mantle endpoint lists "mantle" as well.
Share MCP configuration. Have one team own the MCP servers that connect Claude to your ticketing, logging and documentation, and commit a .mcp.json so everyone benefits. If you need to restrict servers, see managed MCP.
Next steps
- Share install and sign-in instructions; advanced setup covers every install route.
- Add a CLAUDE.md to your main repositories.
- Decide your permission and sandbox policy using organisation setup.