# Conditional Access

If you use [Microsoft Entra Conditional Access policies](https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/overview), you are of course also controlling the access of KONNEKT to your Microsoft 365 resources.

KONNEKT is using different APIs to connect to Microsoft 365. Therefore, it is necessary to configure the corresponding Conditional Access policies to **"All cloud apps"**.&#x20;

It is **not** enough to just select the app "KONNEKT".

<figure><img src="https://2727108687-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8zLVuKYctMIUr68_fs%2Fuploads%2FGoZ6EGN4irb7EujRz8jJ%2Fimage.png?alt=media&#x26;token=3235a881-1487-4923-97fa-4c18805a9c6d" alt=""><figcaption></figcaption></figure>

{% hint style="warning" %}
Make sure, to [grant tenant-wide admin](https://docs.konnekt.io/installation/security/grant-admin-consent-in-enterprise-applications) consent first. Without this, KONNEKT will not be part of "All cloud apps".
{% endhint %}

{% hint style="info" %}
KONNEKT supports Excluded Apps in the corresponding Conditional Access policy starting from KONNEKT 2.10. You must to enable [Enhanced Authentication](https://docs.konnekt.io/configuration/system-settings/enhanced-authentication) to make this work.

Please see also "[Failed to obtain access token](https://docs.konnekt.io/troubleshooting/access-token-issues/failed-to-obtain-access-token)".
{% endhint %}
