# KONNEKT Documentation

Access OneDrive, SharePoint and Teams lightning fast with Windows Explorer

## Overview

KONNEKT brings files that are stored in SharePoint Online document libraries to your Windows File Explorer.

KONNEKT works **online**. It does not sync files to your local disk and waste space there. That is why KONNEKT does a great job in **VDI** environments like **Citrix Virtual Apps**, **Citrix Virtual Desktops**, **Azure Virtual Desktop** (AVD) or **Windows 365 Cloud PC**.

KONNEKT is capable of efficiently handling **big SharePoint Document Libraries** containing over 300,000 files. Explore the use cases described below for additional insights.

![](/files/Uc1RJE4aBUUyFdWrGgSn)

These docs cover the technical aspects of KONNEKT. All other information can be found on <https://konnekt.io/>

## Features

| Features                                                                               | Explanation                                                                                                                     |
| -------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------- |
| [Drive Letter Mapping](/configuration/mappings) and Network Shares                     | Uses a deeply integrated network provider technology. A sophisticated implementation allows UNC paths and drive letter mapping. |
| Explorer Integrated                                                                    | Integrates into the Windows File Explorer structure.                                                                            |
| VDI Support (Citrix and Terminal Services)                                             | Transparent access to any SharePoint from Citrix and Terminal Services                                                          |
| [Multi-tenancy](/installation/configure-office-365-account#multi-tenant-configuration) | Connects to multiple tenants simultaneously                                                                                     |
| [Multi-geo](/configuration/mappings/multi-geo)                                         | Support for OneDrive and SharePoint Online Multi-Geo                                                                            |
| [Co-authoring](/configuration/system-settings/office365-co-authoring)                  | Supports the co-authoring of Microsoft 365 (formerly Office 365)                                                                |

## Use cases

### Type of work

KONNEKT was designed for regular office work on Windows machines (fat clients and VDI).

When it comes to applications, where bigger amounts of data with high throughput are used, like databases, graphics design, video editing or computer aided design (CAD), KONNEKT (and SharePoint Online in general) will most probably not be a satisfactory solution.

Database-files requiring simultaneous access from multiple workstations will not work with KONNEKT (and SharePoint Online in general) by design.

{% hint style="info" %}
KONNEKT is not the appropriate tool to perform data-migrations, where huge amounts of files are moved from legacy repositories to SharePoint Online, or vice versa.
{% endhint %}

### File sizes

KONNEKT is relying on the performance of the network connection to SharePoint Online. Working with files in the one- or two-digit megabyte size is the main use-case.

If you are working with files in the gigabyte size, the performance of your network and SharePoint Online may be an issue. We do not recommend to use KONNEKT in such use-cases and therefore KONNEKT [limits the usage of bigger files by default](/configuration/system-settings/open-file-size-limitations).

### File structure

KONNEKT is doing a great job in several environments. It can handle hundreds of mappings (sites & libraries) and very big libraries with 1 million files or more.

Although there are no issues with the total amount of files or folders within one library, we recommend segmenting the data within the library in folders. A maximum amount of 1000 files per single folder is a good rule of thumb.

### Search

When you use the search function in Windows File Explorer to search in KONNEKT volumes, Windows File Explorer asks for the filenames of the current folder and all subfolders. This works fine for smaller structures (<1000 items in total in all subfolders), depending on the connection speed to Microsoft 365.

{% hint style="info" %}
If you have many items (files, folders) in the current directory or subdirectories, the search in Windows File Explorer may take unacceptably long.

If you need to search in large structures, we strongly recommend using the SharePoint Online web interface.
{% endhint %}

## Architecture

KONNEKT is a client-side tool - there is no backend. **Data is transferred directly between the KONNEKT client and the SharePoint Online services**. Thus, the data neither runs over external systems, nor are they stored on the publisher systems.

KONNEKT uses the **native Microsoft APIs** (Microsoft SharePoint API and Microsoft Graph API) with standard Microsoft authentication to access Microsoft 365. This means that **conditional access** is also effective for access from KONNEKT to SharePoint Online.

## KONNEKT vs. Microsoft OneDrive sync app

The **main differences** between the **OneDrive sync app** and **KONNEKT** are:

| Feature                                                          |                                                                  OneDrive sync app                                                                 |                       KONNEKT                       |
| ---------------------------------------------------------------- | :------------------------------------------------------------------------------------------------------------------------------------------------: | :-------------------------------------------------: |
| Are the files **synced** to the local machine?                   |                                                        <p>Yes</p><p>(at least partially)</p>                                                       |                          No                         |
| Automatically map the SharePoint volumes, the user has access to |                                            <p>No</p><p>(Users mark libraries to be synced manually)</p>                                            |     [Yes](/configuration/mappings/auto-mapping)     |
| **Drive-Letter** support                                         |                                                                         No                                                                         | [Yes](/configuration/mappings/assign-drive-letters) |
| Works in **VDI** environments (e.g. Citrix, AVD, Windows 365)    |                                                                       limited                                                                      |                         Yes                         |
| Support for **UNC** addressing                                   |                                                                         No                                                                         |                         Yes                         |
| <p>Work with big Sites/Libraries<br>(>100 k files)</p>           | [limited](https://support.microsoft.com/en-us/office/restrictions-and-limitations-in-onedrive-and-sharepoint-64883a5d-228e-48f5-b3d2-eb39e07630fa) |                [Yes](#file-structure)               |

You have the option to use KONNEKT side-by-side with Microsoft 365 or stand-alone by replacing the OneDrive sync app. But in every configuration KONNEKT is a helpful leap to the Microsoft 365 ecosystem (Office, Outlook, SharePoint,...) by providing not only the documents and data but also the right options to jump directly to the SharePoint Online Site, providing the links to share or make the versions of a file accessible.


# User manual

This section covers everything end users need to know about working with KONNEKT in Windows File Explorer. It explains the main interface, the system tray menu, and the preferences you can adjust

{% content-ref url="/pages/-MaoV0Yq23jnyOFfsgYT" %}
[Windows File Explorer](/usage/windows-explorer)
{% endcontent-ref %}

{% content-ref url="/pages/-MaoVCqfapQOftQjlKNN" %}
[Tray Menu](/usage/tray-menu)
{% endcontent-ref %}

{% content-ref url="/pages/-MaoVL9Zy-WRUmqlKnTV" %}
[Preferences Menu](/usage/preferences-menu)
{% endcontent-ref %}


# Windows File Explorer

KONNEKT is fully integrated in Windows File Explorer. When you open File Explorer you'll find KONNEKT in the navigation pane.

![](/files/gHPffp7eQ9T5RkP6bw4M)

{% hint style="info" %}
KONNEKT may take 1 to 3 minutes to discover your SharePoint sites, depending on the number of site collections. Please allow sufficient time for the discovery process.
{% endhint %}

{% hint style="success" %}
KONNEKT does NOT download your documents to the client. it is a synchronized view of your SharePoint library.
{% endhint %}

**General** contains four sections:

* Upload
* History
* Offline Files
* Accounts

![](/files/XLXbeARYPB5xeD9MCSfb)

## **Uploads**

The place where the data queue is located, which you're uploading to the SPO. Here you can find all your data if something goes wrong during the upload process (Internet connection lost..). The files will be automatically deleted as long as they are successfully uploaded to the SP.

Once your data is successfully uploaded to the SharePoint Online (SPO), the files in the data queue will be automatically deleted. If there's an issue, such as an internet or wifi disruption, you can find all your data here for troubleshooting.

If there is an issue, you can download stuck files or try to re-upload them by right-clicking on the specific file.

## **History**

The files which you have changed or opened in your sites.

## **Offline Files**

To make **files** available offline from **OneDrive**, right-click on a file, then select Konnekt -> Offline available

![](/files/-MaESEqZ0-QApOTTlZka)

{% hint style="info" %}
The Offline Files feature is only available for files stored on OneDrive
{% endhint %}

## **Accounts**

This feature supports multi-tenancy, allowing you to add multiple Microsoft 365 accounts. You'll find here the accounts you've used to log into your tenant(s).

To add another Microsoft 365 account via right-click and "Add an O365 account."

<figure><img src="/files/B7PeFgLHwDzp1JZpY1HG" alt=""><figcaption></figcaption></figure>

### Existing accounts

If you right-click on an existing user account, the following options will appear:

* Re-authenticate account
* Add share:

  * To map Document Libraries as shares manually.

  <figure><img src="/files/CjQaOeNjuVCsgUQ4KbAu" alt=""><figcaption></figcaption></figure>
* Pause account:
  * To stop the synchronization for this account temporarily.
* Delete account

![](/files/kZxG0i0qw5ZliDieLnFV)


# Tray Menu

Right-click the KONNEKT icon in the taskbar to access the **tray menu** for configuring basic settings. The menu options are as follows:

![](/files/SMm1KRsMpD3A7awDPKHw)

## Version

Shows the current KONNEKT version.

## Check for Update

To update KONNEKT, simply click **Check for update**. KONNEKT will find and install the latest version automatically.

## Last Checked

Shows how much time has passed since the last search for an update.

## Newest version

Displays the most recent version of KONNEKT

## Log

To get an overview of KONNEKT related activities, events and errors. To open it just click on **Log** in the tray menu.

![Log example](/files/HT7iKR8o0NLIRCe0m1H0)

## Exit

If you want to close KONNEKT and stop the connection to SharePoint Online and OneDrive click **Exit** in the tray menu.

{% hint style="info" %}
To restart KONNEKT, click the KONNEKT icon in your Windows Explorer, or re-open it from the Start menu.
{% endhint %}


# Preferences Menu

Under **Preferences** you see the following KONNEKT settings.

![](/files/lusSNvbonIIY7Td2lMve)

There are 3 tabs in the Preferences menu:

* General
* License
* About

### General

The first tab in Preferences is **General**

![](/files/bcRmXJKyMVNP5pIpYgZg)

In this menu you can enable or disable the following settings:

* Enable Office Co-Authoring (enabled by default) \*
* Connect first OneDrive Personal volume to drive `H:`
  * Set the drive letter of your personal OneDrive
* Enable SharePoint Sites
  * If enabled, this setting will display all Site Collections in KONNEKT that you have access to
* Automatically add all Sharepoint document libraries:
  * Enable this setting to display all Document Libraries from a SharePoint Online (SPO) Site Collection

{% hint style="info" %}
Keep in mind that shortcuts may break if this setting is changed. If enabled, KONNEKT will add an additional hierarchy to display all Document Libraries from a Site Collection.
{% endhint %}

It is also possible to change the download directory. Additionally you can select a log level: Off, Error, Info or Debug. Depending on what the user selects, the status messages in the **Log** will change. For more info check [Log level](/configuration/system-settings/logging)

| Log Level | Explanation                                                                                                                                          |
| --------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- |
| Off       | Does not record activities and events.                                                                                                               |
| Error     | Only records errors.                                                                                                                                 |
| Info      | Logs general activities and it logs accesses to SharePoint and cloud storages. This is the default setting.                                          |
| Debug     | Records even more detailed activities and events. Debug is a combination of Error and Info. This logging is the most comprehensive recording method. |

### License

The second tab of preferences is **License**

![](/files/fgOTNArGs9eDCvw3L3Km)

Your license key is visible in the input field (KONNEKT is activated for this key).\
**Licensed to**: Displays the designated licensee and the number of entitled clients.\
**Expires in**: Shows the expiration date of the purchased license.

### About

The last tab is **About** which contains information about the current installed version and a link to the KONNEKT website.

![](/files/KoX7i2VZBPhtlQl6DoQn)


# Deployment

This section walks you through installing and configuring KONNEKT. Start with System Requirements, then proceed to Setup and account configuration.

{% content-ref url="/pages/-Manse1cD2s5Q0BfoS8Z" %}
[System requirements](/installation/system-requirements)
{% endcontent-ref %}

{% content-ref url="/pages/-Manwi3yO7f-RwKgSMwV" %}
[Setup](/installation/setup)
{% endcontent-ref %}

{% content-ref url="/pages/-Mao0rXuKpa0DTlVbn4P" %}
[Configure Office 365 account](/installation/configure-office-365-account)
{% endcontent-ref %}

{% content-ref url="/pages/-ManuC3REI\_Mq\_n9RNhI" %}
[Software updates](/installation/software-updates)
{% endcontent-ref %}


# System requirements

## Client Machine

### Operating System

* **Windows** or\
  **Windows Server**
  * with current and complete system updates and
  * supported by Microsoft via Mainstream Support.
  * Older Windows versions may work - we offer limited support for those systems.

{% hint style="success" %}
KONNEKT runs in different **VDI** environments:

* Hypervisor systems (e.g. Citrix Virtual Desktops, VMware Horizon),
* Multi-session systems (e.g. Citrix Virtual Apps, Microsoft Terminal server/RDS) and
* Microsoft Azure Virtual Desktop (AVD)
* Microsoft Windows 365 (W365) Cloud PC
  {% endhint %}

{% hint style="success" %}
KONNEKT works **independently** from:

* .NET
* specific Citrix versions
* Microsoft 365 Apps (formerly Office 365 ProPlus)
* Microsoft OneDrive sync app
  {% endhint %}

### Processor Platform

* 64 Bit X86 (Intel & AMD)
* 32 Bit X86 (Intel & AMD)
* 64 Bit ARM

## Office 365 Licensing

* **OneDrive for Business** or **SharePoint Online** subscriptions are required for KONNEKT users.

## Proxy Settings

We highly recommend excluding all traffic to Microsoft 365 from proxy usage. For more details, please have a look at [Microsoft's network connectivity principles](https://learn.microsoft.com/en-us/microsoft-365/enterprise/microsoft-365-network-connectivity-principles?view=o365-worldwide).

However, KONNEKT is using the proxy settings of the Windows OS. If a proxy server is set, KONNEKT will use this proxy server.

In detail, KONNEKT calls [WinHttpGetProxyForUrl](https://learn.microsoft.com/en-us/windows/win32/api/winhttp/nf-winhttp-winhttpgetproxyforurl) with the URI <https://graph.microsoft.com> to examine, if a proxy must be used.

{% hint style="success" %}
To bypass your proxy server with traffic from KONNEKT, please make sure, that Windows OS will exclude the URI <https://graph.microsoft.com> from proxy usage.

You may do this by putting this URI on the exclude list in your proxy PAC file.

You should also make sure, that the KONNEKT client can reach [Microsoft Entra ID and SharePoint Online](https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges?view=o365-worldwide) without being interfered by proxy servers or other application layer gateways (ALG) such as firewalls etc.
{% endhint %}

{% hint style="warning" %}
KONNEKT can use proxy servers. However, we offer limited support for clients that are experiencing network connectivity-related issues while connecting to Microsoft 365 via proxy server or other application layer gateways (ALG).
{% endhint %}

## Firewall and Network settings

[It is recommended to](https://learn.microsoft.com/en-us/microsoft-365-apps/best-practices/performance-recommendations) "bypass or allowlist Optimize endpoints on network devices and services that perform traffic interception, SSL decryption, deep packet inspection and content filtering":

* To test network connectivity for Microsoft 365 apps, Microsoft provides [this tool](https://connectivity.office.com/)
* [Office 365 URLs and IP address ranges](https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges?view=o365-worldwide)

**Whitelist Graph API URL**

* The Graph API is a RESTful API that uses HTTPS calls. Each API call uses a unique URL
* To allow for use of different versions of the API, whitelist <https://graph.microsoft.com>

**Whitelist KONNEKT**

* Mandatory for licensing purposes, whitelist [https://license.c4a8.net](https://license.c4a8.net/)
* Users can send us details, when errors occur - <https://crashguard.konnekt.io>

**Microsoft Entra ID**

* Whitelist both endpoints \*.portal.azure.com and portal.azure.com to ensure access to the domain and the subdomains
* [Azure portal URLs for proxy bypass](https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass)
* To troubleshoot network connection issues, check <https://portal.azure.com/selfhelp>


# Security

This section covers the permissions KONNEKT requires in your Microsoft 365 environment and how it interacts with Conditional Access policies.

{% content-ref url="/pages/-MdMqFThWAms0\_6F4\_8Y" %}
[Grant tenant-wide admin consent](/installation/security/grant-admin-consent-in-enterprise-applications)
{% endcontent-ref %}

{% content-ref url="/pages/vr2vfw2KlcEzOqTWSUMD" %}
[Conditional Access](/installation/security/conditional-access)
{% endcontent-ref %}


# Grant tenant-wide admin consent

{% hint style="warning" %}
You have to do the admin consent **before** using KONNEKT with regular users.
{% endhint %}

## Background

KONNEKT is an application that interacts with several Microsoft 365 APIs. Therefore it needs permission to do so in each Microsoft 365 tenant, KONNEKT wants to connect to. One level (but not the only one) of this permission is the Enterprise App Consent in Microsoft Entra ID (formerly Azure AD). It is a major advantage over legacy approaches such as network- or proxy-based access controls for client types, since it is working at every place and allows very granular permissions.

The admin consent for KONNEKT is for "delegated access", only (please see [Microsoft docs](https://learn.microsoft.com/en-us/azure/active-directory/develop/permissions-consent-overview#access-scenarios) for more details on permissions and consent). This basically means that users in this tenant are allowed to use this app to access the requested M365 services/APIs. This does **not** enable the app to access without the user.

### Permission Set: Before Version 2.10

KONNEKT requests the following permissions to be consented:

<table><thead><tr><th width="146.5">API Name</th><th>Claim value</th><th>Permission</th></tr></thead><tbody><tr><td>Microsoft Graph</td><td>User.Read</td><td>Sign in and read user profile</td></tr><tr><td>Office 365 SharePoint Online</td><td>AllSites.Write</td><td>Read and write items in all site collections</td></tr><tr><td>Office 365 SharePoint Online</td><td>MyFiles.Write</td><td>Read and write user files</td></tr><tr><td>Windows Azure Active Directory</td><td>Directory.AccessAsUser.All</td><td>Access the directory as the signed-in user</td></tr><tr><td>Windows Azure Active Directory</td><td>User.Read</td><td>Sign in and read user profile</td></tr></tbody></table>

### Permission Set: Post Version 2.10

{% hint style="warning" %}
Functions exclusively when the setting "[**EnhancedOAuth**](/configuration/system-settings/enhanced-authentication)" is enabled!
{% endhint %}

<table><thead><tr><th width="146.5">API Name</th><th>Claim value</th><th>Permission</th></tr></thead><tbody><tr><td>Microsoft Graph</td><td>Files.ReadWrite.All</td><td>Have full access to all files user can access</td></tr><tr><td>Microsoft Graph</td><td>Sites.Read.All</td><td>Read items in all site collections</td></tr><tr><td>Microsoft Graph</td><td>User.Read</td><td>Sign in and read user profile</td></tr><tr><td>Office 365 SharePoint Online</td><td>AllSites.Read</td><td>Read items in all site collections</td></tr></tbody></table>

[Since some of the permissions require to be consented by an admin](https://learn.microsoft.com/en-us/graph/permissions-reference), you have to do the admin consent before using KONNEKT with regular users.

You can learn more about [managing consent to applications and evaluate consent requests in the Microsoft docs](https://learn.microsoft.com/en-us/azure/active-directory/manage-apps/manage-consent-requests).

## Add KONNEKT permissions in Microsoft Entra ID Enterprise Applications

As an admin (or having a role that allows granting admin consent) you can grant tenant-wide admin consent to **KONNEKT** by using the following "Magic URL":

App registration URL till KONNEKT version **2.9.1** and below:

```
https://login.microsoftonline.com/{tenant-id}/adminconsent?client_id=fbaaaa6a-1ad0-4ac5-9c4c-4ce9353dc6cf
```

App registration URL from KONNEKT version **2.10** and later:

```
https://login.microsoftonline.com/{tenant-id}/adminconsent?client_id=11fa31bb-2024-4f49-8b38-f458d596a81a
```

Therefore you need your`tenant-id`which you get from the **Azure portal** under **Microsoft Entra ID:**

![](/files/-MgeIa7clVi4Eo5cpnv3)

{% hint style="info" %}
Don't forget to delete the `{}` from the link
{% endhint %}

**After that:**

1. Open the link.
2. Login using your admin account (or account with role allows granting admin consent).
3. Accept the KONNEKT permissions request.
4. Done!

{% hint style="info" %}
If you get **Page Not Found** after accepting the consent, please ignore it. It has no meaning here.
{% endhint %}

To check **KONNEKT** permissions you can find it in **Microsoft Entra ID** under **Enterprise applications** -> **Permissions**

<figure><img src="/files/nzzjR299d6V4xMvG5uEO" alt=""><figcaption></figcaption></figure>

For more Info about admin consent visit [MS.Docs](https://docs.microsoft.com/en-us/azure/active-directory/manage-apps/grant-admin-consent)

## Delete KONNEKT permissions from Microsoft Entra ID Enterprise Applications

In case you want to remove the admin-consent for KONNEKT, please proceed the following steps:

1. Sign in to the **Azure portal** with a role that allows deleting admin consent.
2. Select **Microsoft Entra ID** then **Enterprise applications.**
3. Look for **Konnekt** and click on it.
4. Select **properties.**
5. **Delete**, and confirm the delete.

<figure><img src="/files/cxVHzbtbvAG0LGtqYsRf" alt=""><figcaption></figcaption></figure>


# Conditional Access

If you use [Microsoft Entra Conditional Access policies](https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/overview), you are of course also controlling the access of KONNEKT to your Microsoft 365 resources.

KONNEKT is using different APIs to connect to Microsoft 365. Therefore, it is necessary to configure the corresponding Conditional Access policies to **"All cloud apps"**.

It is **not** enough to just select the app "KONNEKT".

<figure><img src="/files/KRSqN2wfZX6jSwj9d1k8" alt=""><figcaption></figcaption></figure>

{% hint style="warning" %}
Make sure, to [grant tenant-wide admin](/installation/security/grant-admin-consent-in-enterprise-applications) consent first. Without this, KONNEKT will not be part of "All cloud apps".
{% endhint %}

{% hint style="info" %}
KONNEKT supports Excluded Apps in the corresponding Conditional Access policy starting from KONNEKT 2.10. You must to enable [Enhanced Authentication](/configuration/system-settings/enhanced-authentication) to make this work.

Please see also "[Failed to obtain access token](/troubleshooting/access-token-issues/failed-to-obtain-access-token)".
{% endhint %}


# Setup

{% hint style="info" %}
It's recommended to restart your device following any installation or update.
{% endhint %}

## Security

To setup KONNEKT you first have to meet the security requirements:

* admin consent
* conditional access config (if used)

Please see [here](/installation/security) for details.

## Download current setup files

You can get the latest version of KONNEKT [here](https://trial.konnekt.io/).

If you want (as an admin) to grant tenant-wide consent for KONNEKT please visit [here](/installation/security/grant-admin-consent-in-enterprise-applications)

## Interactive Installation

{% hint style="warning" %}
This KONNEKT setup requires local admin permissions.
{% endhint %}

You can install KONNEKT by running the MSI file interactively. The setup dialog will start:

<figure><img src="/files/9YxeZshhh4AWudPKmtla" alt=""><figcaption></figcaption></figure>

Click next.

<figure><img src="/files/jqDZCs3mdonmdrNe3AEI" alt=""><figcaption></figcaption></figure>

Accept the license terms and click next.

<figure><img src="/files/wcdbi1WqgNqnOy6hYmQ4" alt=""><figcaption></figcaption></figure>

You may then enter your license key.

{% hint style="info" %}
If you do not enter a license key, you start a 14 days trial version.
{% endhint %}

<figure><img src="/files/67ueLW1gbqnAssOiQFjD" alt=""><figcaption></figcaption></figure>

KONNEKT is now ready to start the setup.

<figure><img src="/files/X3p2279GqgQzAFs63DTJ" alt=""><figcaption></figcaption></figure>

Click Finish to finalize the setup.

After the installation is successfully finished, a pop up window shows up automatically to connect your Microsoft 365 (formerly Office 365) account and grant the required permissions to create an Enterprise Application in your tenant (see screenshots below).

<figure><img src="/files/lJevs6F5z297oSZ3OX8i" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/MV9lY1G0thlDBhyT6UCl" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
To grant the permissions, you have to log in with an admin account or an account that has permissions to create an Enterprise Application in your tenant.

To grant the permissions tenant-wide please check [Grant tenant-wide admin consent](/installation/security/grant-admin-consent-in-enterprise-applications)
{% endhint %}

## Silent Installation

If you want a silent installation without any user interface interaction you can use the following [msiexec](https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/msiexec) command after downloading the msi installation file from [here ](https://trial.konnekt.io/)and rename it to `konnekt`:\
\
`msiexec /quiet /qn /norestart /i konnekt.msi LICENSE_KEY=<YourKey>`

Instead of the `<YourKey>` in the end, enter your license key.

{% hint style="info" %}
After the trial period, it is recommended to set the license key to machine level (HKLM).
{% endhint %}


# Configure Office 365 account

KONNEKT leverages the user's account in Microsoft Entra ID (formerly Azure AD) to access SharePoint Online.

## Single Sign On (SSO)

If your system is configured for single sign-on (SSO) with Microsoft Entra ID, KONNEKT will automatically set up your account.

## Manual Account Configuration

If your system is not configured for single sign-on (SSO) with Microsoft Entra ID, KONNEKT will open a dialog to set up the account:

![](/files/OAo1o258ztMSLelqTTYj)

Click on "Connect your Office 365 Account".

KONNEKT will open the Microsoft Entra ID sign-in page:

![](/files/UzAne039HIeWowLSXeVL)

Sign in with your Microsoft Entra ID account.

## Autologin Mapping

After the successful setup of the Office 365 account, KONNEKT will start to search for SharePoint Online sites in the corresponding tenant, which the user has access to. KONNEKT will automatically map the default document libraries of those sites in the Windows File Explorer.

![](/files/9NEn4a4ZutUcvjAAugCI)

If needed, libraries can be mapped to a specific driver letter (see [Assign drive letter to a KONNEKT folder](/configuration/mappings/assign-drive-letters)).

## Multi-Tenant Configuration

With KONNEKT it is possible to work with multiple tenants simultaneously. Just open the Windows Explorer with KONNEKT selected on the left pane and right-click on **Accounts.**

<figure><img src="/files/-M9cf7HXxH-Hz8B_fYWm" alt="Right-click menu on Accounts in the KONNEKT Explorer pane, showing the &#x22;Add O365 account&#x22; command"><figcaption></figcaption></figure>

{% hint style="info" %}
You cannot add guest accounts from foreign M365 tenants. Only members can be added.
{% endhint %}

Log in with the account for the tenant you want to add.


# Software updates

## How do I know?

If a software update is available, KONNEKT informs the user with a toast, if the user has local admin privileges.

You may alternatively observe the context menu of the KONNEKT tray icon (right click), if there is a new version available.

![](/files/dNlxdSy1o9dRsBdrPAUq)

## Manual download of current setup files

You can get the latest version of KONNEKT [here](https://trial.konnekt.io/).

## Preview Releases

Sometimes we publish KONNEKT Preview Releases. We do this, when we are working on a new version of KONNEKT, to give customers the opportunity to try new features before those are finally released. We are happy, when we get feedback on those versions, to find bugs and improve release quality.

{% hint style="info" %}
Preview Releases are still in development and therefore bugs may occur.
{% endhint %}

KONNEKT Preview Releases are not published via the built-in update-checker in KONNEKT. You have to manually download it. If a preview release is available, you can find it in the [changelog](/changelog).

## Executing the update

Please follow the following steps to update KONNEKT:

1. Run the MSI of [the most current KONNEKT version](/changelog)
2. Reboot the machine if needed

{% hint style="warning" %}
**Local admin permissions** are required to execute an update of KONNEKT.
{% endhint %}

{% hint style="info" %}
Why do I have to reboot the machine?

An important module of KONNEKT is a kernel driver. This kind of drivers can be updated during a reboot, only.
{% endhint %}

{% hint style="warning" %}
**Restart vs. Shutdown**

If KONNEKT setup requests a restart, please do so. Please be aware that shutting down a Windows machine and start it up again may not be equal to a restart. Many modern Windows machines use hibernation for shutdown by default. In this case driver updates may fail.
{% endhint %}

## Recommended update procedure

Managed FAT clients should be updated by the client management system (e.g. Microsoft Intune).

Multiuser VDI servers should be updated manually by admins.


# Advanced Configuration

This section covers all advanced configuration options for KONNEKT, including policy management through Intune and Group Policy, mapping settings, and system-level behavior. Start with Management Options to choose your preferred configuration method.

{% content-ref url="/pages/-Mhs0Y-xWN81wJsRr7N4" %}
[Management options](/configuration/management-options)
{% endcontent-ref %}

{% content-ref url="/pages/-Mhs0lqfZs\_5G7e8q648" %}
[Mappings](/configuration/mappings)
{% endcontent-ref %}

{% content-ref url="/pages/-Mhs8YurpIlBEL4-E7x2" %}
[GUI Settings](/configuration/gui-behavior)
{% endcontent-ref %}

{% content-ref url="/pages/OVShNsQh1RrlrdQrO48e" %}
[System settings](/configuration/system-settings)
{% endcontent-ref %}

{% content-ref url="/pages/-Mhs9b8-pXuph1UmAEaU" %}
[Other](/configuration/other)
{% endcontent-ref %}


# Management options

{% content-ref url="/pages/zfAWWdfmkrPPoTxWWF4z" %}
[Settings for Intune-managed devices (Import custom ADMX- Public preview)](/configuration/management-options/setting-for-intune-managed-devices)
{% endcontent-ref %}

{% content-ref url="/pages/-MeYuSNJfZmNQwm8yNRA" %}
[Settings for Intune-managed devices (Legacy)](/configuration/management-options/setting-for-intune-managed-devices-1)
{% endcontent-ref %}

{% content-ref url="/pages/-M\_UwOEoxi46dAxpSPTF" %}
[Settings via GPO](/configuration/management-options/settings-via-gpo)
{% endcontent-ref %}

## ADMX / ADML files

You can download the ADMX / ADML files here:

{% file src="/files/JpjDHWdJF40X7RbChwgg" %}


# Settings for Intune-managed devices (Import custom ADMX- Public preview)

## Basics

Microsoft has recently published a new Intune feature to make importing custom ADMX and ADML templates possible.

Once templates are imported, you can create a device configuration policy using these settings, and then assign the policy to your managed devices.

This feature applies to:

* Windows 11
* Windows 10

For more information about the import see <https://learn.microsoft.com/en-us/mem/intune/configuration/administrative-templates-import-custom>

## Download

You can **download** the ADMX / ADML file [here](/configuration/management-options#admx-adml-files).

## **Usage**

{% hint style="info" %}
After importing the ADMX,ADML files, you have to choose by creating the configuration profile "Imported Administrative templates (Preview)" to find KONNEKT policies.
{% endhint %}

<figure><img src="/files/cSYbqniCpf6HfRtsrIOl" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/Csytb3uIZJJHCZPIxTrC" alt=""><figcaption></figcaption></figure>


# GUI settings

{% hint style="info" %}
Most of the policies are applicable to version 2.0 and above
{% endhint %}

### Available GUI settings

<figure><img src="/files/HRWe2MpiPiDB9uA5vfqx" alt=""><figcaption></figcaption></figure>

For more information about the policies please check [GUI Settings](/configuration/gui-behavior)


# Mappings

### Available mapping settings

<figure><img src="/files/QOixvrELEXcT3S1WR1L4" alt=""><figcaption></figcaption></figure>

For more information about the policies please check [Mappings](/configuration/mappings)


# System settings

### Available system settings

<figure><img src="/files/6zfLkvJ4LVia9PrYgLd5" alt=""><figcaption></figcaption></figure>

For more information about the policies please check [System settings](/configuration/system-settings)


# Settings for Intune-managed devices (Legacy)

Starting in Windows 10, version 1703, you can import ADMX files (also called ADMX ingestion) and set those ADMX-backed policies for Win32 and Desktop Bridge apps by using Windows 10 Mobile Device Management (MDM) on desktop SKUs. The ADMX files that define policy information can be ingested to your device by using the Policy CSP URI, The ingested ADMX file is then processed into MDM policies.

![](/files/-MeZ0cFyesFnlrsO9asB)

For more in information please visit [Understanding ADMX-backed policies](https://docs.microsoft.com/en-us/windows/client-management/mdm/understanding-admx-backed-policies) and [Policy CSP](https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-configuration-service-provider)

## Ingesting KONNEKT ADMX file **and deploying policies**

In order to set the KONNEKT policies you need to ingest the admx file in a configuration profile first:

1\. Go to the **Microsoft Intune admin center**\
2\. Click on **Devices**, then in the sub-menu go to **Configuration profiles**\
3\. **Create profile:** Select Platform **Windows 10 and later,** profile type **Templates,** in search field choose **Custom,** then **Create**

![](/files/-MeZ5574lSLojZlV32k4)

4\. Now choose a **Name** for this profile, **Next**\
5\. Under **Configuration settings:**

**First you have to** ingest the admx file: **Add** new Row

Click on **Add** then in the new window:

* **Name:** choose a name, e.g. KonnektAdmxIngesting
* **OMA-URI:**

```
./Vendor/MSFT/Policy/ConfigOperations/ADMXInstall/Konnekt/Policy/KonnektAdmx

```

* **Data type:** String
* **Value:** copy the content of this [admx file](/configuration/management-options#admx-adml-files), then **Save**

![](/files/-MeZQmSuKrJw6r2fSwuR)

Now add all policies you need to assign to clients from the [Available Intune Policies](#available-intune-policies).

{% hint style="info" %}
In the following picture 4 policies are added (as an example). After ingesting the admx file, you can choose the policies you need to push to your clients from the tables [Available Intune Policies](#available-intune-policies)
{% endhint %}

![](/files/-MeZMErCQE8qCmd1EA9s)

6\. Assign the policies to groups/users, and **Next, Next, and Create**

\
After a successful Sync for assigned devices/users restart **KONNEKT** to apply the new policies.

To check that the URI's have been deployed correctly in your MDM go to **Devices -> Windows -> your Device -> Device configuration -> your configuration profile**

![](/files/-MeZWt722KsiC2l__sGm)

To check configured URI's on the machine go to the following path in the Registry:

```
[HKCU or HKLM]\SOFTWARE\Policies\GlueckKanja\Konnekt
```

{% hint style="info" %}
Choose **HKCU** for user policies or **HKLM** for machine policies.
{% endhint %}

![](/files/-MeZTBBh1dn2AFstyQYU)

## Available Intune Policies

To deploy the following OMA-URI's in Intune MDM please [check here](#ingesting-konnekt-admx-file-and-deploying-policies)

{% hint style="danger" %}
URI's are case-sensitive!
{% endhint %}

{% hint style="info" %}
Most of the policies are applicable to version 2.0 and above
{% endhint %}

{% content-ref url="/pages/mCt4FFLbgmza0ftUTptQ" %}
[Intune GUI settings](/configuration/management-options/setting-for-intune-managed-devices-1/intune-gui-settings)
{% endcontent-ref %}

{% content-ref url="/pages/13HTzrDSC3EBFys38LbP" %}
[Intune mappings](/configuration/management-options/setting-for-intune-managed-devices-1/intune-mappings)
{% endcontent-ref %}

{% content-ref url="/pages/mEHuLvzj8TgbDtiFBhpD" %}
[Intune system settings](/configuration/management-options/setting-for-intune-managed-devices-1/intune-system-settings)
{% endcontent-ref %}

{% content-ref url="/pages/3WhnM5VNS47lkMM4NaOM" %}
[Intune other settings](/configuration/management-options/setting-for-intune-managed-devices-1/intune-other-settings)
{% endcontent-ref %}


# Intune GUI settings

{% hint style="info" %}
Most of the policies are applicable to version 2.0 and above
{% endhint %}

## Language

**Name:** Konnekt-Language

**OMA-URI**

User context:

```
./User/Vendor/MSFT/Policy/Config/Konnekt~Policy~Konnekt~ExplorerUI/Language
```

Device context:

```
./Device/Vendor/MSFT/Policy/Config/Konnekt~Policy~Konnekt~ExplorerUI/Language
```

**Data type:** String

**Value**

```
<enabled/>
<data id="LanguageSelect" value="en-US"/>
```

**Note**

As value use `en-US` for English or `de-DE`for German

## Account re-authentication UI

**Name:** Konnekt-Account-re-authentication-UI

**OMA-URI**

User context:

```
./User/Vendor/MSFT/Policy/Config/Konnekt~Policy~Konnekt~ExplorerUI/PopupReauthenticateAccount
```

Device context:

```
./Device/Vendor/MSFT/Policy/Config/Konnekt~Policy~Konnekt~ExplorerUI/PopupReauthenticateAccount
```

**Data type:** String

**Value options**

```
<enabled/>
```

```
<disabled/>
```

**Note**

For more information about the policy, see [Account re-authentication](/configuration/gui-behavior/account-reauthentication)

## Konnekt Explorer UI

**Name:** Konnekt-Explorer-UI

**OMA-URI**

User context:

```
./User/Vendor/MSFT/Policy/Config/Konnekt~Policy~Konnekt~ExplorerUI/ShellNode
```

Device context:

```
./Device/Vendor/MSFT/Policy/Config/Konnekt~Policy~Konnekt~ExplorerUI/ShellNode
```

**Value**

```
<enabled/> 
<data id="ShellUploads" value="true"/>
<data id="ShellHistory" value="true"/>
<data id="ShellOfflineFiles" value="true"/>
<data id="ShellAccounts" value="true"/>
```

**Note**

To hide one (or more) component, change the value to `false`. For more information about the policy, see [Explorer UI](/configuration/gui-behavior/konnekt-explorer-ui)

#### **Example:**

Show **Uploads, History,** and **Offline Files** and hide **Account**

```
<enabled/>
<data id="ShellUploads" value="true"/>
<data id="ShellHistory" value="true"/>
<data id="ShellOfflineFiles" value="true"/>
<data id="ShellAccounts" value="false"/>
```

#### **Result**

![](/files/MZV3wwtsecqEk0W8yhMY)

## Tray icon

Name: Konnekt-Tray-Icon

**OMA-URI**

User context:

```
./User/Vendor/MSFT/Policy/Config/Konnekt~Policy~Konnekt~ExplorerUI/ShowTrayIcon
```

Device context:

```
./Device/Vendor/MSFT/Policy/Config/Konnekt~Policy~Konnekt~ExplorerUI/ShowTrayIcon
```

**Value options**

```
<enabled/>
```

```
<disabled/>
```

**Note**

For more information about the policy, see [Hide tray icon](/configuration/gui-behavior/hide-tray-icon)


# Intune mappings

## Add SharePoint libraries

**Name:** Konnekt-Automatically-Add-All-SharePoint-Libraries

**OMA-URI**

User context:

```
./User/Vendor/MSFT/Policy/Config/Konnekt~Policy~Konnekt~Mappings/AddAllSharepointLibraries
```

Device context:

```
./Device/Vendor/MSFT/Policy/Config/Konnekt~Policy~Konnekt~Mappings/AddAllSharepointLibraries
```

**Data type:** String

**Value options**

```
<enabled/>
```

```
<disabled/>
```

**Note**

For more information about the policy, see [Map all document libraries](/configuration/mappings/auto-mapping#map-all-document-libraries)

## Connect Drive

**Name:** Konnekt-Connect-Drive

**OMA-URI**

User context:

```
./User/Vendor/MSFT/Policy/Config/Konnekt~Policy~Konnekt~Mappings/ConnectDrive
```

Device context:

```
./Device/Vendor/MSFT/Policy/Config/Konnekt~Policy~Konnekt~Mappings/ConnectDrive
```

**Data type:** String

**Value options**

```
<enabled/> <data id="DriveSelect" value="F:"/>
```

Disable connect drive letter mapping

```
<enabled/> <data id="DriveSelect" value="disabled"/>
```

**Note**

Choose value from `F:` to `Z:` For more information about the policy, see [Assign drive letter](/configuration/mappings/assign-drive-letters)

## SharePoint site query

**Name:** Konnekt-SharePoint-Site-Query

**OMA-URI**

User context:

```
./User/Vendor/MSFT/Policy/Config/Konnekt~Policy~Konnekt~Mappings/SharepointSiteQuery
```

Device context:

```
./Device/Vendor/MSFT/Policy/Config/Konnekt~Policy~Konnekt~Mappings/SharepointSiteQuery
```

**Data type:** String

**Value**

```
<enabled/>
<data id="SharepointSiteQuery" value="your query"/>
```

**Note**

For more information about the policy and the query, see [Auto mapping](/configuration/mappings/auto-mapping#site-scope)

## SharePoint Usage

**Name:** Konnekt-SharePoint-Usage

**OMA-URI**

User context:

```
./User/Vendor/MSFT/Policy/Config/Konnekt~Policy~Konnekt~Mappings/O365SharepointUsage
```

Device context:

```
./Device/Vendor/MSFT/Policy/Config/Konnekt~Policy~Konnekt~Mappings/O365SharepointUsage
```

**Data type:** String

**Value options**

```
<enabled/>
```

```
<disabled/>
```

**Note**

For more information about the policy, see [Map default document libraries](/configuration/mappings/auto-mapping#map-default-document-libraries)

## Multi-Geo

{% hint style="info" %}
Available for KONNEKT 2.1 or newer
{% endhint %}

**Name:** Konnekt-Multi-Geo

**OMA-URI**

User context:

```
./User/Vendor/MSFT/Policy/Config/Konnekt~Policy~Konnekt~Mappings/SharepointMultiGeo
```

Device context:

```
./Device/Vendor/MSFT/Policy/Config/Konnekt~Policy~Konnekt~Mappings/SharepointMultiGeo
```

**Data type:** String

**Value options**

```
<enabled/>
```

```
<disabled/>
```

**Note**

For more information about the policy, see [Multi-Geo](/configuration/mappings/multi-geo)

## Sharepoint Sites

{% hint style="info" %}
Available for KONNEKT 2.1 or newer
{% endhint %}

**Name:** Konnekt-SharePoint-Sites

### **OMA-URI**

User context:

```
./User/Vendor/MSFT/Policy/Config/Konnekt~Policy~Konnekt~Mappings/SharepointSites
```

Device context:

```
./Device/Vendor/MSFT/Policy/Config/Konnekt~Policy~Konnekt~Mappings/SharepointSites
```

**Data type:** String

### **Value options**

To map one site, use the following syntax and replace <mark style="color:blue;">\<URL1></mark> with your site/library URL (<mark style="color:blue;">\<URL1></mark> must be added twice as in the following syntax and be separated by "<mark style="color:green;">\&#xF000;</mark>"):

*\<enabled/>*\
*<<mark style="color:red;">data id</mark>="<mark style="color:green;">SharepointSites\_List</mark>" <mark style="color:red;">value</mark>="<mark style="color:blue;">\<URL1></mark><mark style="color:green;">\&#xF000;</mark><mark style="color:blue;">\<URL1></mark>" />*

To map multiple sites, use the following syntax and replace <mark style="color:blue;">\<URL1></mark> with your first site/library URL and <mark style="color:orange;">\<URL2></mark> with your second site/library URL, and so on (each URL should be added twice as in the following syntax):

*\<enabled/>*\
*<<mark style="color:red;">data id</mark>="<mark style="color:green;">SharepointSites\_List</mark>" <mark style="color:red;">value</mark>="<mark style="color:blue;">\<URL1></mark><mark style="color:green;">\&#xF000;</mark><mark style="color:blue;">\<URL1></mark><mark style="color:green;">\&#xF000;</mark><mark style="color:orange;">\<URL2></mark><mark style="color:green;">\&#xF000;</mark><mark style="color:orange;">\<URL2></mark>" />*

To disable the policy

```
<disabled/>
```

### **Example**

#### **Site 1**

* Site URI = `https://konnektdemo.sharepoint.com/sites/TestSite1`
* Assigned Name = `TestSite1Name`
* Assigned drive letter = `k:`

KONNEKT URL for this site mapping would be:

*<mark style="color:blue;"><https://konnektdemo.sharepoint.com/sites/TestSite1|TestSite1Name|k>:</mark>*

#### **Site 2**

* Site URI = `https://konnektdemo.sharepoint.com/sites/TestSite2`
* Assigned Name = `TestSite2Name`
* Assigned drive letter = `m:`

KONNEKT URL for this site mapping would be:

*<mark style="color:orange;"><https://konnektdemo.sharepoint.com/sites/TestSite2|TestSite2Name|m>:</mark>*

#### **Resulting Intune Policy String Value**

*\<enabled/>*\
*<<mark style="color:red;">data id</mark>="<mark style="color:green;">SharepointSites\_List</mark>" <mark style="color:red;">value</mark>="<mark style="color:blue;"><https://konnektdemo.sharepoint.com/sites/TestSite1|TestSite1Name|k>:</mark><mark style="color:green;">\&#xF000;</mark><mark style="color:blue;"><https://konnektdemo.sharepoint.com/sites/TestSite1|TestSite1Name|k>:</mark><mark style="color:green;">\&#xF000;</mark><mark style="color:orange;"><https://konnektdemo.sharepoint.com/sites/TestSite2|TestSite2Name|m>:</mark><mark style="color:green;">\&#xF000;</mark><mark style="color:orange;"><https://konnektdemo.sharepoint.com/sites/TestSite2|TestSite2Name|m>:</mark>" />*

### **Note**

For more information about the policy and how to set the URL with examples, see [Managed mappings](/configuration/mappings/managed-mappings)


# Intune system settings

## Cache

**Name:** Konnekt-Cache

**OMA-URI**

User context:

```
./User/Vendor/MSFT/Policy/Config/Konnekt~Policy~Konnekt~SystemSettings/Cache
```

Device context:

```
./Device/Vendor/MSFT/Policy/Config/Konnekt~Policy~Konnekt~SystemSettings/Cache
```

**Data type:** String

**Value**

```
<enabled/>
<data id="CacheTTL" value="60"/>
<data id="CacheSize" value="1000"/>
```

**Note**

For more information about the policy and setting the value, see [Cache settings](/configuration/system-settings/cache-setting)

## Co-Authoring

**Name:** Konnekt-Co-Authoring

**OMA-URI**

User context:

```
./User/Vendor/MSFT/Policy/Config/Konnekt~Policy~Konnekt~SystemSettings/CoAuthoring
```

Device context:

```
./Device/Vendor/MSFT/Policy/Config/Konnekt~Policy~Konnekt~SystemSettings/CoAuthoring
```

**Data type:** String

**Value options**

```
<enabled/>
```

```
<disabled/
```

**Note**

For more information about the policy, see [Office365 Co-Authoring](/configuration/system-settings/office365-co-authoring)

## Offline attribute

**Name:** Konnekt-Offline-Attribute

**OMA-URI**

User context:

```
./User/Vendor/MSFT/Policy/Config/Konnekt~Policy~Konnekt~SystemSettings/OfflineAttribute
```

Device context:

```
./Device/Vendor/MSFT/Policy/Config/Konnekt~Policy~Konnekt~SystemSettings/OfflineAttribute
```

**Data type:** String

**Value options**

```
<enabled/>
```

```
<disabled/>
```

**Note**

For more information about the policy, see [Offline attribute](/configuration/system-settings/offline-attribute)

## Offline attribute filter

**Name:** Konnekt-Offline-Attribute-Filter

**OMA-URI**

User context:

```
./User/Vendor/MSFT/Policy/Config/Konnekt~Policy~Konnekt~SystemSettings/OfflineAttributeFilter
```

Device context:

```
./Device/Vendor/MSFT/Policy/Config/Konnekt~Policy~Konnekt~SystemSettings/OfflineAttributeFilter
```

**Data type:** String

**Value**

```
<enabled/>
<data id="OfflineAttributeFilter" value="your list of extensions, see Note"/>
```

**Note**

For more information about the policy and setting the value, see [Offline attribute filter](/configuration/system-settings/offline-attribute#exclude-dedicated-file-types-from-offline-attribute-filter)

## Link scope

**Name:** Konnekt-Link-Scope

**OMA-URI**

User context:

```
./User/Vendor/MSFT/Policy/Config/Konnekt~Policy~Konnekt~SystemSettings/SharePointLinkScope
```

Device context:

```
./Device/Vendor/MSFT/Policy/Config/Konnekt~Policy~Konnekt~SystemSettings/SharePointLinkScope
```

**Data type:** String

**Value**

```
<enabled/>
<data id="SharepointLinkScopeSelect" value="see Note"/>
```

**Note**

For more information about the policy and setting the value, see [Link scope](/configuration/system-settings/link-scope)

## Log level

{% hint style="info" %}
Available for KONNEKT 2.1 or newer
{% endhint %}

**Name:** Konnekt-Log-Level

**OMA-URI**

User context:

```
./User/Vendor/MSFT/Policy/Config/Konnekt~Policy~Konnekt~SystemSettings/LogLevel
```

Device context:

```
./Device/Vendor/MSFT/Policy/Config/Konnekt~Policy~Konnekt~SystemSettings/LogLevel
```

**Data type:** String

**Value**

```
<enabled/>
<data id="LogLevelSelect" value="see Note"/>
```

**Note**

For more information about the policy and setting the value, see [Log level](/configuration/system-settings/logging)

## Update check

{% hint style="info" %}
Available for KONNEKT 2.1 or newer
{% endhint %}

**Name:** Konnekt-Update-Check

**OMA-URI**

User context:

```
./User/Vendor/MSFT/Policy/Config/Konnekt~Policy~Konnekt~SystemSettings/UpdateInterval
```

Device context:

```
./Device/Vendor/MSFT/Policy/Config/Konnekt~Policy~Konnekt~SystemSettings/UpdateInterval
```

**Data type:** String

**Value options**

```
<enabled/>
<data id ="UpdateInterval" value="120"/>
```

```
<disabled/>
```

**Note**

For more information about the policy, see [Update checker](/configuration/system-settings/update-checker)


# Intune other settings

## Set license key

**Name:** Konnekt-Set-License-Key

**OMA-URI**

User context:

```
./User/Vendor/MSFT/Policy/Config/Konnekt~Policy~Konnekt/License
```

Device context:

```
./Device/Vendor/MSFT/Policy/Config/Konnekt~Policy~Konnekt/License
```

**Data type:** String

**Value**

```
<enabled/>
<data id="License" value="your key"/>
```

**Note**

For more information about the policy, see [Set license key](/configuration/other/license-key-on-multi-user-environments)


# Settings via GPO

## Registry key location

**Settings** are stored in:\
\
`HKEY_CURRENT_USER\SOFTWARE\GlueckKanja\Konnekt`

`HKEY_LOCAL_MACHINE\SOFTWARE\GlueckKanja\Konnekt`

**Policies** are stored in:

`HKEY_CURRENT_USER\SOFTWARE\Policies\GlueckKanja\Konnekt`

`HKEY_LOCAL_MACHINE\SOFTWARE\Policies\GlueckKanja\Konnekt`

## ADMX file

To use group policies for KONNEKT please use the attached ADMX Template. For scenarios where a language file is needed please see the language folder in the ZIP file.

With the ADMX Template the following settings can be set:

![](/files/aXWwwpvAK7XOu91cnZou)

You can **download** the ADMX/ADML files [here](/configuration/management-options#admx-adml-files).

## **GPO / Registry key priorities**

KONNEKT evaluates the settings of the GPO / registry in this order:

1. HKEY\_LOCAL\_MACHINE (HKLM)
2. HKEY\_CURRENT\_USER (HKCU)

## Preferences Menu Behavior

Some of the settings are also available in the preferences menu:

![](/files/u74xBzo6whMELEaluB7L)

If a GPO is enforced, the corresponding setting in the preferences menu will still be shown but disabled for user change.


# GUI Settings

{% content-ref url="/pages/-Mei0MHzYjFiAWmTan\_t" %}
[Account re-authentication](/configuration/gui-behavior/account-reauthentication)
{% endcontent-ref %}

{% content-ref url="/pages/EdtqFpemmQDp9KWpyRI2" %}
[Change KONNEKT name in explorer](/configuration/gui-behavior/change-konnekt-name-in-explorer)
{% endcontent-ref %}

{% content-ref url="/pages/-MeirUXTlBLYI9Sf6qa6" %}
[Explorer UI](/configuration/gui-behavior/konnekt-explorer-ui)
{% endcontent-ref %}

{% content-ref url="/pages/-MeYroWs76bWs9aT0xVf" %}
[Hide tray icon](/configuration/gui-behavior/hide-tray-icon)
{% endcontent-ref %}


# Account re-authentication

{% hint style="info" %}
This policy is applicable to version 2.0 and above
{% endhint %}

This policy controls if the login dialog pops up immediately if an account needs to be re-authenticated.

### **Definition**

**Policy name:** `Account Reauthentication UI`

**Policy Group:** KONNEKT / GUI Settings

| Policy Setting    | Behavior                                                                                                                                                            |
| ----------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Not configured    | The default is used (enabled).                                                                                                                                      |
| Enabled (default) | The login dialogue is shown, if an account needs to be re-authenticated.                                                                                            |
| Disabled          | The login dialogue is **not** shown, if an account needs to be re-authenticated. An error is indicated in the tray and in the KONNEKT node in Windows File Explorer |

{% hint style="warning" %}
To apply the policy you have to restart **KONNEKT**
{% endhint %}

**Policies** are stored in:

`HKEY_CURRENT_USER\SOFTWARE\Policies\GlueckKanja\Konnekt`

`HKEY_LOCAL_MACHINE\SOFTWARE\Policies\GlueckKanja\Konnekt`

### **Apply the policy**

1. Via GPO, see [settings via GPO](/configuration/management-options/settings-via-gpo)
2. Pushing policies via Intune, see [settings for Intune Managed Devices](/configuration/management-options/setting-for-intune-managed-devices-1)


# Change KONNEKT name in explorer

By editing the following registry key, you can change the name of KONNEKT in Windows Explorer to a preferred name e.g. File Server, SharePoint files, company name, etc.

### **Key paths**

You have to change the "(Default)" values in the following two registry keys:

Key for 64 bit apps:

```
Computer\HKEY_CLASSES_ROOT\CLSID\{6E619E0D-21EB-4471-A40B-040815C884EF}
```

Key for 32 bit apps:

```
Computer\HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{6E619E0D-21EB-4471-A40B-040815C884EF}
```

Change the value of the "(Default)" REG\_SZ to whatever name you would like. By default it is `KONNEKT`.

In the following example, we changed it to `SharePoint Data`

![](/files/1BFSKoao0flTARluHN7m)

### **Result**

![](/files/97iR6Mvi2xdwZyR7cDsq)


# Explorer UI

{% hint style="info" %}
This policy is applicable to version 2.0 and above
{% endhint %}

This policy defines which components of the Konnekt explorer node are shown and which are not.

Konnekt has 4 components shown in the Explorer window: **Uploads**, **History**, **Offline Files,** and **Accounts**

![](/files/jGRIdCcSJa7eIfLkko9B)

**Example:** Show Uploads, History, Offline Files and hide Accounts (to prevent users adding new M365 accounts)

![](/files/RrkUmA73jTFzXbdgW8aS)

{% hint style="warning" %}
To apply the policy you have to restart the **Windows Explorer** process, no need to restart **KONNEKT**
{% endhint %}

**Result:**

![](/files/jD6SppxplufBmgh24Kqc)

### **Policy information**

**Policy name:** Konnekt Explorer UI

### Registry

**Key names:** `ShellAccounts, ShellHistory, ShellOfflineFiles, ShellRestricted, ShellUploads`\
**Key type:** REG\_DWORD (32-Bit Value)

## **There are several ways to apply the policy:**

* manually by adding the key in the registry under machine or user registry settings
* via GPO, see [settings via GPO](/configuration/management-options/settings-via-gpo)
* pushing policies via Intune, see [settings for Intune Managed Devices](/configuration/management-options/setting-for-intune-managed-devices-1/intune-gui-settings#konnekt-explorer-ui)

**Policies** stored in:

`HKEY_CURRENT_USER\SOFTWARE\Policies\GlueckKanja\Konnekt`

`HKEY_LOCAL_MACHINE\SOFTWARE\Policies\GlueckKanja\Konnekt`


# Hide tray icon

{% hint style="info" %}
This policy is applicable to version 2.0 and above
{% endhint %}

This policy controls if KONNEKT shows an icon in the window's start bar tray area.

If the policy is enabled, the tray icon is shown. If the policy is disabled, no tray icon is visible. Users can restart KONNEKT with the `/ui` option to have a tray icon.

![](/files/ncZlrOjdeaph5jvEFOQM)

{% hint style="warning" %}
To apply the policy you have to restart **KONNEKT**
{% endhint %}

### **Policy information:**

**Policy Name:** Tray Icon

### Registry

**Key names:** `ShowTrayIcon`\
**Key type:** REG\_DWORD (32-Bit Value)<br>

## **There are several ways to apply the policy:**

* manually by adding the key in the registry under machine or user registry settings
* via GPO, see [settings via GPO](/configuration/management-options/settings-via-gpo)
* pushing policies via Intune, see [settings for Intune Managed Devices](/configuration/management-options/setting-for-intune-managed-devices-1/intune-gui-settings#tray-icon)

**Policies** stored in:

`HKEY_CURRENT_USER\SOFTWARE\Policies\GlueckKanja\Konnekt`

`HKEY_LOCAL_MACHINE\SOFTWARE\Policies\GlueckKanja\Konnekt`


# Mappings

Mappings control which SharePoint Site Collections and Document Libraries appear in your users' File Explorer. Auto Mapping is the recommended starting point for most organizations.

{% content-ref url="/pages/-M\_Uw7T2CenwbNY9RWSx" %}
[Additional document libraries](/configuration/mappings/add-a-document-library)
{% endcontent-ref %}

{% content-ref url="/pages/-Mb235Taehto9WssHbcF" %}
[Assign drive letters](/configuration/mappings/assign-drive-letters)
{% endcontent-ref %}

{% content-ref url="/pages/-Mhs20LhYFV1P7y7WW-W" %}
[Auto mapping](/configuration/mappings/auto-mapping)
{% endcontent-ref %}

{% content-ref url="/pages/-MhJ4iMLxWUFgmStRoKA" %}
[Managed mappings](/configuration/mappings/managed-mappings)
{% endcontent-ref %}

{% content-ref url="/pages/h5OLBr8YivL52Dcr6txL" %}
[Multi-Geo](/configuration/mappings/multi-geo)
{% endcontent-ref %}


# Additional document libraries

## Add additional document libraries

By default, KONNEKT uses the default document libraries from a SharePoint site. But you can add further document libraries to KONNEKT.

Do the following to add a further document library:

1. Open KONNEKT in the Windows Explorer
2. Click on **Accounts**
3. Right-click on the account
4. Select **Add share**

![](/files/-MA66DEFxcRW7sH0VR0P)

5\. Enter the document library URL in the dialog which opens then

![](/files/-Mam0837PSJVATQ0q-Da)

6\. Choose the right library you want to add

![](/files/-Mam0Lwmn6bVtW6lya7I)

7\. You can change the name of your share. This name will appear in KONNEKT.

Now the document library will be added and is available via the KONNEKT menu in the Windows Explorer.

{% hint style="warning" %}
This feature offers you to add only public libraries. To add a private channel library, see [Teams private and shared channels](/configuration/mappings/auto-mapping#teams-private-and-shared-channels).
{% endhint %}

## Remove additional document libraries

A manually added document library can be removed using the following steps:

1. Right-click on the added document library
2. Navigate to **Konnekt**
3. Click **Remove share**

![](/files/E0Heg1I9MqCA352uXibf)


# Assign drive letters

## Assign driver letter to OneDrive for Business library

With this setting, you can configure a drive letter for the OneDrive for Business library.

The default value is `H:`

You can configure this feature with the following options alternatively:

### Preferences menu

![](/files/YiQJuDHDa7lR8pVGxy9L)

### GPO/Intune

Please use our [ADMX template](/configuration/management-options#admx-adml-files) to configure this setting or via Intune management.

Policy name: `Connect drive`

{% hint style="info" %}
After applying the policy, restarting the machine is required
{% endhint %}

#### KONNEKT 2.6.0 and newer:

| Policy-setting |                   Value                   | Behavior                                                                                                                                                                                |
| :------------: | :---------------------------------------: | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Not configured |                    N/A                    | <p>KONNEKT will assign H: to the OneDrive for Business document library by default.<br>User can change the setting in the preferences menu.<br>OneDrive is mapped to H: by default.</p> |
|    Disabled    |                    N/A                    | <p>KONNEKT will not assign any drive letter to the OneDrive for Business document library.<br>User can not change the setting in the preferences menu.</p>                              |
|     Enabled    | <p>\<drive-letter>:</p><p>(e.g. "H:")</p> | <p>KONNEKT will assign the configured drive letter to the OneDrive for Business document library.<br>User can not change the setting in the preferences menu.</p>                       |

#### KONNEKT older than 2.6.0

| Policy-setting |                   Value                   | Behavior                                                                                                                                                                                                                                                                                  |
| :------------: | :---------------------------------------: | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Not configured |                    N/A                    | <p>KONNEKT will assign H: to the OneDrive for Business document library by default.<br>User can change the setting in the preferences menu.<br>OneDrive is mapped to H: by default.</p>                                                                                                   |
|    Disabled    |                    N/A                    | KONNEKT will assign and map the default drive letter! To disable drive mappings to the OneDrive for Business document library, you should enable the policy and set the **Drive** under **Options** to **Disabled.** Config item in preferences menu will be disabled for change by user. |
|     Enable     |                 "Disabled"                | KONNEKT will not assign a drive letter to the OneDrive for Business document library. Config item in preferences menu will be disabled for change by user.                                                                                                                                |
|     Enable     | <p>\<drive-letter>:</p><p>(e.g. "H:")</p> | KONNEKT will assign the configured drive letter to the OneDrive for Business document library. Config item in preferences menu will be disabled for change by user.                                                                                                                       |

### Registry

**Key name:** `ConnectDrive`\
**Key type:** REG\_SZ (String Value)

## Assign drive letters to other folders using "net use"

You can assign a drive letter to a KONNEKT folder, by using the *`net use`* command.

**Usage**

```
net use <DRIVE-LETTER>: <KONNEKT-UNC-PATH> [/PERSISTENT:{YES | NO}]
```

For more information on the *`net use`* command see [here](https://ss64.com/nt/net-use.html), or run `net use /?` in your command prompt.

{% hint style="info" %}
Make sure to run CMD without admin rights to avoid any connecting errors for normal users.
{% endhint %}

{% hint style="info" %}
**Note:** if the name of Folder contains spaces you have to but the UNC-Path in " " like in the next example.
{% endhint %}

**Example:**

![](/files/-McJ8qmWBFa_BVHDlvEW)

**Result:**

![](/files/C1KCnLZvDvc90tJVxkYT)

## Assign drive letters with Managed Mappings

You can map drive letters to sites and libraries with [Managed Mappings](/configuration/mappings/managed-mappings).

## **There are several ways to apply the policy:**

* manually by adding the key in the registry under machine or user registry settings
* via GPO, see [settings via GPO](/configuration/management-options/settings-via-gpo)
* pushing policies via Intune, see [settings for Intune Managed Devices](/configuration/management-options/setting-for-intune-managed-devices-1/intune-mappings#connect-drive)

**Policies** stored in:

`HKEY_CURRENT_USER\SOFTWARE\Policies\GlueckKanja\Konnekt`

`HKEY_LOCAL_MACHINE\SOFTWARE\Policies\GlueckKanja\Konnekt`


# Auto mapping

Auto Mapping is the feature of KONNEKT, that automatically maps all SharePoint Online sites & document libraries into the users Windows File Explorer (and other file dialogues). Only sites & libraries, the user has access to, are mapped.

Administrators can control this feature on two levels:

1. Site level
2. Library level

KONNEKT updates the mappings every 60 minutes.

{% hint style="info" %}
KONNEKT uses SharePoint Online Search's default 'Result Source.' Modifying this setting could alter the Site Collections and Document Libraries displayed.
{% endhint %}

{% hint style="info" %}
Using Microsoft's "[Restrict discovery of SharePoint sites and content](https://learn.microsoft.com/en-us/sharepoint/restricted-content-discovery)" setting may affect what Site Collections are displayed within KONNEKT.
{% endhint %}

## Site scope

{% hint style="info" %}
This policy is applicable to version 2.0 and above
{% endhint %}

{% hint style="info" %}
By default KONNEKT will map all team and communication sites and subsites the user has access to. Private channels of Teams are not in the default site scope.

**If you are fine with that, you do not need to use this policy.**
{% endhint %}

### **Policy** Definition

* **Policy Name (ADMX):** `Sharepoint Sites Query`

This policy enables you to define the query string used to find SharePoint sites.

The site query needs to be expressed in KQL. You can find general KQL documentation here: <https://docs.microsoft.com/en-us/sharepoint/dev/general-development/keyword-query-language-kql-syntax-reference>

A list of query properties for SharePoint can be found here: <https://docs.microsoft.com/en-us/sharepoint/technical-reference/crawled-and-managed-properties-overview>

You can test your KQL site query at this SharePoint Online URL:

```
https://<YourTenantName>.sharepoint.com/_layouts/15/osssearchresults.aspx
```

In the following paragraphs, you can find some examples for KQL query strings.

### Default

If you do not configure this policy, KONNEKT will use the following default KQL query:

```
(webtemplate:STS OR webtemplate:GROUP OR webtemplate:SITEPAGEPUBLISHING) AND (contentclass=STS_Site OR contentclass=STS_Web)
```

This will map all team and communication sites, the user has access to. Private channels of Teams are not in the default site scope

![](/files/i8qHNMySLOdoK8mpAlTx)

### Examples

#### Sites whitelisting

<details>

<summary>Filter on site name/title</summary>

`Title="<MySiteName>"`

**Query String** to map only the sites "Give" and "Leadership"

```
(webtemplate:STS OR webtemplate:GROUP OR webtemplate:SITEPAGEPUBLISHING) AND (contentclass=STS_Site OR contentclass=STS_Web) AND (title="Give" OR title="Leadership")
```

**Note:** restarting KONNEKT is required to apply the policy

</details>

![](/files/PpQk4vV26yssAJGUJ4TW)

{% hint style="info" %}
**Note:** To show all sites with \<Leadership> in the name, use the operator **(:)** instead of **(=)** by title
{% endhint %}

#### Sites whitelisting using \* operator

<details>

<summary>Filter on site name/title using (*) operator</summary>

Show all sites has a word starting with Con `title:<"Con*">`

**Query string**

```
(webtemplate:STS OR webtemplate:GROUP OR webtemplate:SITEPAGEPUBLISHING) AND (contentclass=STS_Site OR contentclass=STS_Web) AND (title:"Con*")
```

</details>

{% hint style="info" %}
**Note**: We do not recommend combining the **(=)** operator together with asterisk **(\*)** when you do exact matching. Instead, use the **(:)** operator with **(\*)**
{% endhint %}

#### Sites blacklisting

<details>

<summary>Exclude sites per site name/title</summary>

Map all sites and libraries except specific sites (and their libraries)

**Query string** to exclude `<Site01>` and `<Site02>`

```
(webtemplate:STS OR webtemplate:GROUP OR webtemplate:SITEPAGEPUBLISHING) AND (NOT (sitetitle:"Site01" OR sitetitle:"Site02"))
```

**Note:** restarting KONNEKT is required to apply the policy

</details>

#### Teams private and shared channels

<details>

<summary>Add Microsoft Teams private and shared channels</summary>

Map all SP sites, Teams private channels and Teams shared channels

By adding `webtemplate:TEAMCHANNEL` to the query

**Query string**

```
(webtemplate:STS OR webtemplate:GROUP OR webtemplate:SITEPAGEPUBLISHING OR webtemplate:TEAMCHANNEL) AND (contentclass=STS_Site OR contentclass=STS_Web)
```

**Note:** restarting KONNEKT is required to apply the policy

Since private and shared channels are dedicated sites on SharePoint, they appear as dedicated volumes in KONNEKT.

</details>

#### All Subsites for multiple SharePoint sites

<details>

<summary>Show all Subsites of one or more SharePoint sites</summary>

To map all Subsites (and Libraries) of one or more SharePoint sites, you can use the following query

**Query string**

```
(webtemplate:STS OR webtemplate:GROUP OR webtemplate:SITEPAGEPUBLISHING) AND (contentclass=STS_Site OR contentclass=STS_Web) AND (path:https://<YourTenantName>.sharepoint.com/sites/MySite1 OR path:https://<YourTenantName>.sharepoint.com/sites/MySite2)
```

**Note:** change MySite1 and MySite2 to your SharePoint site names.

You map Subsites and libraries of only one SharePoint site or even add multiple URLs if needed

</details>

### **There are several ways to apply the policy:**

* manually by adding the key in the registry under machine or user registry settings
* via GPO, [check settings via GPO](/configuration/management-options/settings-via-gpo)
* pushing policies via Intune, see [settings for Intune Managed Devices](/configuration/management-options/setting-for-intune-managed-devices-1/intune-mappings#sharepoint-site-query)

#### **Manual setting in the registry**

{% hint style="info" %}
You do not need this if you use GPO or Intune management.
{% endhint %}

* **Registry Value name:** `SharepointSiteQuery`
* **Registry Value type:** `REG_SZ`
* **Registry Value data:** KQL string
* **Registry Value storage location**:
  * `HKEY_CURRENT_USER\SOFTWARE\Policies\GlueckKanja\Konnekt`\
    or
  * `HKEY_LOCAL_MACHINE\SOFTWARE\Policies\GlueckKanja\Konnekt`

## Library scope

### Map default document libraries

If enabled the setting "Enable Sharepoint Sites" will display all default libraries from all Site Collections where a user has access to.

A user can set this setting via the preferences menu:

![](/files/2tyB7ylmD5FeqzpbYDUU)

It can be configured via registry/GPO/MDM as well:

**Policy Name (ADMX):** Sharepoint Sites Autodiscovery

![](/files/H6D0ZVI7OtJtfZGbmmpZ)

#### Registry

Key name: **O365SharepointUsage**\
Key type: REG\_DWORD

Enable or disable access to SharePoint Online sites.

| Function |           Value          | Behavior                                                                                                                          |
| :------: | :----------------------: | --------------------------------------------------------------------------------------------------------------------------------- |
|  Disable |             0            | KONNEKT maps the OneDrive for Business library, only.                                                                             |
|  Enable  | <p>1</p><p>(default)</p> | KONNEKT maps the OneDrive for Business and all default document libraries of the SharePoint Online sites, the user has access to. |

The default value is 1 (enable).

We recommend using our [ADMX template](/configuration/management-options/settings-via-gpo#admx-file) to configure this setting.

### Map all document libraries

You can find this setting in the preferences menu:

![](/files/tSmhPusGwwfypMKplO3K)

{% hint style="info" %}
Please make sure to reboot **KONNEKT** after changing this setting.
{% endhint %}

You can also configure this setting via registry/GPO/MDM:

**Policy Name (ADMX):** Add all sharepoint libraries

![](/files/FlLW7ntrVULIGSsTBqFg)

#### Registry

Key name: **AddAllSharepointLibraries**\
Type: REG\_DWORD

| Function |           Value          | Behavior                                                                                                                                                                                              |
| :------: | :----------------------: | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|  Disable | <p>0</p><p>(default)</p> | <p>KONNEKT will map the default document library of the SharePoint Online sites, only.</p><p>Format of the UNC addressing is:<br><code>\OneDrive-\<tenant-name>\&#x3C;site-name>...</code></p>        |
|  Enable  |             1            | <p>KONNEKT will map all document libraries of the SharePoint Online site.</p><p>Format of the UNC addressing is:<br><code>\OneDrive-\<tenant-name>\&#x3C;site-name>\&#x3C;library-name>...</code></p> |

The default value is 0 (disable)

{% hint style="danger" %}
If users in your company are using different values of this setting, their UNC paths will not be compatible with each other (e.g. when they exchange UNC links).

To prevent this, ensure that this setting is set for all users correctly.
{% endhint %}

We recommend using our [ADMX template](/configuration/management-options/settings-via-gpo#admx-file) to configure this setting.

## **There are several ways to apply the policy:**

* manually by adding the key in the registry under machine or user registry settings
* via GPO, see [settings via GPO](/configuration/management-options/settings-via-gpo)
* pushing policies via Intune, see [settings for Intune Managed Devices](/configuration/management-options/setting-for-intune-managed-devices-1/intune-mappings#add-sharepoint-libraries)


# Managed mappings

{% hint style="info" %}
This policy is applicable to version 2.0 and above
{% endhint %}

## Policy description

By using the feature Managed Mappings (policy name `"Sharepoint Sites"`), you can map specific SharePoint sites and libraries to your KONNEKT. You can additionally define drive letters to those mappings.

{% hint style="info" %}
If enabled, this setting will map drives regardless of a users permissions.
{% endhint %}

To add mappings, go to the policy and click on **Show\...**

![](/files/-MhNYGTgWW-aPhfM96Qs)

![](/files/kR5k6rvC1O7vyahTQqgr)

{% hint style="info" %}
Using this policy for drive-letter mapping will always map the default document library as root.

To map all libraries of one site you need to map the site and enable the policy [AddAllSharePointLibraries](/configuration/mappings/auto-mapping#map-all-document-libraries)

If you specify a library in the URL, only this library will be directly mapped.

This policy does not support folder mapping, for folder mapping please use **net use** as described [here](/configuration/mappings/assign-drive-letters#assign-drive-letters-to-other-folders-using-net-use).

We have a feature-request in the backlog to improve the flexibility of mappings in a future version of KONNEKT.
{% endhint %}

{% hint style="warning" %}
SharePoint **Subsites** are **currently not supported** with KONNEKT Managed Mappings. Please use Auto Mapping to use Subsites with KONNEKT, instead.

We have a feature-request in the backlog to improve the flexibility of mappings in a future version of KONNEKT.

Please also note [Microsoft's recommendations regarding subsites](https://learn.microsoft.com/en-us/office365/servicedescriptions/sharepoint-online-service-description/sharepoint-online-limits#subsites), as subsites have limited scalability and can cause performance issues.
{% endhint %}

## **Policy definition**

**Policy name:** `Sharepoint Sites`

**Syntax of site definition:**

```
<sharepoint-url>[|<Name>[|<DriveLetter>[|<TenantName>[|<Favorite>]]]]
```

* <mark style="background-color:blue;">`<sharepoint-url>:`</mark> Your sharepoint site/library URL. Must be URL encoded (e.g. Spaces are represented by `%20`).\
  If you are mapping your root site (requires KONNEKT 2.7.0 or newer), please make sure to have a slash at the end of the <mark style="background-color:blue;">`<sharepoint-url>`</mark> . Example:\
  Your root site: `https://contoso.sharepoint.com`\
  The Managed Mapping should look like this: `https://contoso.sharepoint.com/|RootSite|R:`
* `<Name>:` Name you choose for the mapped site. This name must be unique for each mapping.\
  *optional => value may be empty*
* `<DriveLetter>:` Drive letter for drive mapping.\
  *optional => value may be empty*
* `<TenantName>:` Microsoft 365 tenant name for the corresponding account that must be used to access this site. (\<TenantName>.onmicrosoft.com).\
  *optional => value may be empty*
* `<Favorite>:` Indicate if mapping shall be a KONNEKT favorite. You must run KONNEKT 2.2.1 or newer for this feature to work properly.\
  Possible values:\
  \- `FALSE` (default)\
  \- `TRUE`\
  *optional => value may be empty*

**Site mapping result:**

![](/files/-MhSVkSm0f_ANwwCiL_w)

**Drive mapping result:**

![](/files/-MhSUyyroUR533LcXaYZ)

## **Examples**

#### All libraries of a site

```
https://mytenant.sharepoint.com/sites/mysite
```

This will map the **default document library** of this site. The drive will be labeled as "mysite"

{% hint style="info" %}
To map all libraries you need to enable the policy [AddAllSharePointLibraries](/configuration/mappings/auto-mapping#map-all-document-libraries)
{% endhint %}

#### Dedicated library of a site

```
https://mytenant.sharepoint.com/sites/mysite/Shared%20Documents|MySite Docs
```

This will add the "shared documents" library of the site "mysite". The Drive will be labeled "MySite Docs".

#### Assign a drive letter

```
https://mytenant.sharepoint.com/sites/mysite/Shared%20Documents|MySite Docs|M:
```

This will add the "shared documents" library of the site "mysite". The Drive will be labeled "MySite Docs". The network path will be mapped to drive M.

#### Map foreign tenant

```
https://foreignTenant.sharepoint.com/sites/mysite||X:|ForeignTenant
```

This will add all document libraries of the site "mysite", from the tenant "ForeignTenant.onmicrosoft.com". The network path will be mapped to drive X.

The user must have an account configured in KONNEKT, that belongs to Microsoft Entra ID in the tenant "ForeignTenant".

#### Make mapping a KONNEKT favorite

```
https://mytenant.sharepoint.com/sites/mysite/Shared%20Documents|MySite Docs|||TRUE
```

This will add the "shared documents" library of the site "mysite". The Drive will be labeled "MySite Docs". It will be added as KONNEKT favorite.

## **There are several ways to apply the policy**

1. via GPO, see [settings via GPO](/configuration/management-options/settings-via-gpo)
2. pushing policies via Intune, see [settings for Intune Managed Devices](/configuration/management-options/setting-for-intune-managed-devices-1)
3. manually by adding the key in the registry under machine or user registry settings

{% hint style="warning" %}
We highly recommend to use 1. or 2., since this policy has several components.
{% endhint %}

## Manual setting in registry

{% hint style="info" %}
You do not need this, if you use GPO or Intune management.
{% endhint %}

The policy consists of two components in the registry:

1. **Value** (activate the feature)
2. **Key with value per mapping** (describe every single mapping)

#### **1. Value**

* **Value name:** `SharepointSites`
* **Value type:** `REG_DWORD`
* **Value data:** `1` (to activate the feature)
* Value **stored** in:
  * `HKEY_CURRENT_USER\SOFTWARE\Policies\GlueckKanja\Konnekt`\
    or
  * `HKEY_LOCAL_MACHINE\SOFTWARE\Policies\GlueckKanja\Konnekt`

#### **2. Key with value per mapping**

* **Key name:** `SharepointSites`
* Key **stored** in:
  * `HKEY_CURRENT_USER\SOFTWARE\Policies\GlueckKanja\Konnekt`\
    or
  * `HKEY_LOCAL_MACHINE\SOFTWARE\Policies\GlueckKanja\Konnekt`

Under this key, one value/data entry has to be generated per mapping:

* **Value name:** equals Value data
* **Value type:** `REG_SZ`
* **Value data:** see [Policy definition](#policy-definition).
* Value **stored** in:
  * `HKEY_CURRENT_USER\SOFTWARE\Policies\GlueckKanja\Konnekt\SharepointSites`\
    or
  * `HKEY_LOCAL_MACHINE\SOFTWARE\Policies\GlueckKanja\Konnekt\SharepointSites`


# Multi-Geo

{% hint style="info" %}
Available for KONNEKT version 2.1 or later
{% endhint %}

{% hint style="success" %}
For machines with KONNEKT 2.3 or later, the policy is ignored as Multi-Geo support is always enabled.
{% endhint %}

Using this policy, you can activate support for [OneDrive and SharePoint Online Multi-Geo](https://learn.microsoft.com/en-us/microsoft-365/enterprise/multi-geo-capabilities-in-onedrive-and-sharepoint-online-in-microsoft-365?view=o365-worldwide) in KONNEKT.

**Policy name:** `Multi-Geo Sharepoint support`

![](/files/WNl2bE3suXps5e7iKqj1)

<table><thead><tr><th width="232.33333333333331"></th><th></th><th></th></tr></thead><tbody><tr><td>Function</td><td>Value</td><td>Behavior</td></tr><tr><td>not set</td><td>N/A</td><td>Multi-Geo is de-activated</td></tr><tr><td>enabled</td><td>1</td><td>Multi-Geo is activated</td></tr><tr><td>disabled</td><td>0</td><td>Multi-Geo is de-activated</td></tr></tbody></table>

You can find more details on OneDrive and SharePoint Online Multi-Geo [here](https://docs.microsoft.com/en-us/microsoft-365/enterprise/multi-geo-capabilities-in-onedrive-and-sharepoint-online-in-microsoft-365?view=o365-worldwide).

## **There are several ways to apply the policy**

1. Via GPO, see [settings via GPO](/configuration/management-options/settings-via-gpo)
2. Pushing policies via Intune, see [settings for Intune Managed Devices](/configuration/management-options/setting-for-intune-managed-devices-1)
3. Manually by adding the key in the registry

### Manual setting in the registry

{% hint style="info" %}
You do not need this if you use GPO or Intune management
{% endhint %}

* **Value name:** `SharepointMultiGeo`
* **Value type:** `REG_DWORD`
* **Value data:** `1` (to activate the feature), `0` to disable it
* **Value stored** **in**:
  * `HKEY_CURRENT_USER\SOFTWARE\Policies\GlueckKanja\Konnekt`\
    or
  * `HKEY_LOCAL_MACHINE\SOFTWARE\Policies\GlueckKanja\Konnekt`


# System settings

These settings control KONNEKT's core behavior including caching, authentication, file size limits, and throttling prevention. All settings can be deployed via Intune (ADMX / ADML) or Group Policy.

{% content-ref url="/pages/psXuuw5w8iVXSS7tSnNC" %}
[Authentication browser engine](/configuration/system-settings/authentication-browser-engine)
{% endcontent-ref %}

{% content-ref url="/pages/-MejWWIM6M4lWhXuEHXW" %}
[Cache settings](/configuration/system-settings/cache-setting)
{% endcontent-ref %}

{% content-ref url="/pages/-Mbg8sh4zsOwGzzv2Mc5" %}
[Skip Account Wizard](/configuration/system-settings/configure-konnekt-for-a-subset-of-users)
{% endcontent-ref %}

{% content-ref url="/pages/q8SZv5nKYJbY9kPenccO" %}
[Link scope](/configuration/system-settings/link-scope)
{% endcontent-ref %}

{% content-ref url="/pages/bHW0ME0XmKjTUR2MoKA8" %}
[Logging](/configuration/system-settings/logging)
{% endcontent-ref %}

{% content-ref url="/pages/-Mb22SrSzr8DJUIY-6IN" %}
[Office365 Co-Authoring](/configuration/system-settings/office365-co-authoring)
{% endcontent-ref %}

{% content-ref url="/pages/03mm2qeq7WwxE0Roi4v4" %}
[Offline attribute](/configuration/system-settings/offline-attribute)
{% endcontent-ref %}

{% content-ref url="/pages/Aunh7LrjvlrACgwkPKKo" %}
[Open file size limitations](/configuration/system-settings/open-file-size-limitations)
{% endcontent-ref %}

{% content-ref url="/pages/nNYVOK4XOOFDgrwIb78c" %}
[SharePoint throttling prevention](/configuration/system-settings/throttling-prevention/sharepoint-throttling-prevention)
{% endcontent-ref %}

{% content-ref url="/pages/aGzSlk0M3x8w7ui36zeB" %}
[Update checker](/configuration/system-settings/update-checker)
{% endcontent-ref %}


# Authentication browser engine

{% hint style="info" %}
This policy is applicable to version 2.9 and above.
{% endhint %}

This policy controls whether KONNEKT uses the Edge (Chromium) web browser component WebView2.

{% hint style="success" %}
To set this policy, you need the [ADMX/ADML](https://docs.konnekt.io/configuration/management-options#admx-adml-files) files 2.9.0 and above.
{% endhint %}

### Definition

**Policy name:** Disable Edge Browser Component (WebView2)

**Policy group:** KONNEKT / System Settings

| Policy setting     | Behavior                                                                                   |
| ------------------ | ------------------------------------------------------------------------------------------ |
| Not configured     | The default is used (disabled).                                                            |
| Enabled            | KONNEKT will not use WebView2, instead Internet Explorer based control is used.            |
| Disabled (default) | KONNEKT will try to use WebView2. If it fails it will use Internet Explorer based control. |

{% hint style="warning" %}
To apply the policy you have to restart **KONNEKT**
{% endhint %}

**Policies** are stored in:

`HKEY_CURRENT_USER\SOFTWARE\Policies\GlueckKanja\Konnekt`

`HKEY_LOCAL_MACHINE\SOFTWARE\Policies\GlueckKanja\Konnekt`

To set it up for a single user, create this **Registry** key:

Computer\HKEY\_CURRENT\_USER\Software\GlueckKanja\Konnekt

**Value name** (DWORD 32 bit): DisableWebView2

**Value data:** 1

### **Apply the policy**

1. Manually by adding the key in the registry under machine or user registry settings
2. Via GPO, see [settings via GPO](/configuration/management-options/settings-via-gpo)
3. Pushing policies via Intune, see [settings for Intune Managed Devices](/configuration/management-options/setting-for-intune-managed-devices-1)


# Cache settings

{% hint style="info" %}
This policy is applicable to version 2.0 and above
{% endhint %}

## Basics

All files, that are read from or written to SharePoint Online via KONNEKT are temporarily cached on the local disc.

The cache directory is located at: `%localappdata%\konnekt\cache`

This policy defines the caching behavior of KONNEKT.

KONNEKT uses the cache for different purposes:

* Files that are currently opened by the user
* Files that need to be uploaded (write cache)
* Files that are closed (read cache)

## **Definitions**

### **Cache TTL (Time To Live)**

How long (in minutes) closed documents (read cache) will stay in the Cache. Without this setting, TTL remains automatically at 60 minutes - at "Normal pressure". This value needs to be filled in the input field if the policy is enabled. The cache is always cleared after a restart of KONNEKT.

* Dimension: Minutes
* Minimum Value: 0
* Maximum Value:
  * 2880 (KONNEKT releases < 2.6.0)
  * 60480 (KONNEKT release 2.6.0 or newer)

### **Fixed Cache Size**

How big (in Megabytes) is the KONNEKT cache folder. This value needs to be filled in the input field if the policy is enabled.

* Dimension: Megabytes
* Minimum Value: 0 => cache size will be calculated from free disk space (default)
* Maximum Value: 20000

## **Behind the scenes**

### Pressure states

The cache operates in different pressure states:

* **Normal pressure:** The cache is utilized below critical values. Closed files will be kept in the read cache up to the TTL value.
* **High read pressure:** The cache is filled up with too many closed files. The read cache will be deleted.
* **High write pressure:** The cache is holding lots of files queued for upload. Further, write operations will be throttled in order to empty the upload queue.
* **Critical write pressure:** The cache is nearly filled up with files queued for upload. Further, write operations will be throttled significantly in order to empty the upload queue.
* **Cache full:** The cache is completely occupied. Requests to open further files will be rejected.

### Automatic cache size calculation

* **Cache size from free disk calculation**\
  *sizeMax* = (*FreeDiskSize* + *CacheSize*) \* 75%
* **High pressure calculation**\
  *pressure* = *sizeUsed* / *sizeMax* >= 80%
* **High write pressure calculation**\
  *writePressure* = *uploadSize* / *sizeMax* >= 60%
* **Critical write pressure calculation**\
  *writePressure* = *uploadSize* / *sizeMax* >= 80%
* **Cache filled calculation**\
  *sizeUsed* >= *sizeMax*

{% hint style="warning" %}
To apply the policy you have to **restart the machine**
{% endhint %}

## **There are several ways to apply the policy:**

* manually by adding the key in the registry under machine or user registry settings
* via GPO, [check settings via GPO](/configuration/management-options/settings-via-gpo)
* pushing policies via Intune, see [setting for Intune Managed Devices](/configuration/management-options/setting-for-intune-managed-devices-1/intune-system-settings#cache)

![](/files/-MeiqtYcZxh6MsREPeNn)

#### **Policies** stored in:

`HKEY_CURRENT_USER\SOFTWARE\Policies\GlueckKanja\Konnekt`

`HKEY_LOCAL_MACHINE\SOFTWARE\Policies\GlueckKanja\Konnekt`

{% hint style="warning" %}
To apply the policy you have to **restart the machine**
{% endhint %}

## Recommendations for VDI environments

We recommend the following settings for VDI environments in general, but please make sure, that this setting fit your use-case of KONNEKT:

**Cache TTL**: 10-60 min

**Cache Size**: 500-1000 MB

You may also want to [restrict the file size](/configuration/system-settings/open-file-size-limitations), that you are reading from SharePoint Online:

**OneDriveOpenFilesLargerThanReadOnly**: 100-500 MB (= 104,857,600 - 524,288,000 bytes)

**OneDriveDoNotOpenFilesLargerThan**: 200-1000 MB (= 209,715,200 - 1,048,576,000 bytes)


# Download Directory

The Download Directory is the path where KONNEKT saves files to, that the user wants to recover.

The typical use-case is, that an error happened during the transfer of a file to SharePoint Online. In this case KONNEKT will show an error in Windows File Explorer. One option for users is to "[export file to download folder](/troubleshooting/how-to-deal-with-error-s)".

You can find more about handling errors [here](/troubleshooting/access-token-issues/error-message-about-missing-token).

## Default location

The default location for the Download Directory is `%USERPROFILE%\Downloads`.

## Set by user

Users can change the location manually in the preferences dialog, as long as the policy is not set.

<figure><img src="/files/d0tAdJDmHDdSE635Fl6a" alt=""><figcaption></figcaption></figure>

## Policy

{% hint style="info" %}
This policy is available in KONNEKT 2.6.0 or newer
{% endhint %}

### **Definition**

**Policy name:** `Download Directory`

**Policy Group:** KONNEKT / System Settings

| Policy Setting | Behavior                                                                                                                                      |
| -------------- | --------------------------------------------------------------------------------------------------------------------------------------------- |
| Not configured | The user-setting/default is used.                                                                                                             |
| Enabled        | The Download Directory configured in the policy is used by KONNEKT. The user can not change the Download Directory via the preference dialog. |
| Disabled       | The user-setting/default is used.                                                                                                             |

### **Apply the policy**

1. Via GPO, see [settings via GPO](/configuration/management-options/settings-via-gpo)
2. Pushing policies via Intune, see [settings for Intune Managed Devices](/configuration/management-options/setting-for-intune-managed-devices-1)

{% hint style="warning" %}
Make sure to use the most current [ADMX file](/configuration/management-options/settings-via-gpo#admx-file), that matches your KONNEKT version.
{% endhint %}


# Enhanced Authentication

Enhanced Authentication enables KONNEKT to use improved [OAuth 2.0 authorization](https://learn.microsoft.com/en-us/entra/identity-platform/v2-oauth2-auth-code-flow#protocol-details).

{% hint style="danger" %}
By enabling this setting:

* **A new** [**Azure app registration**](/installation/security/grant-admin-consent-in-enterprise-applications) **is required**
* Users need to reauthenticate!
* Namespaces are built from [default domain](https://learn.microsoft.com/en-us/microsoft-365/admin/setup/domains-faq?view=o365-worldwide#how-do-i-set-or-change-the-default-domain-in-microsoft-365) (\\\onedrive-\<DefaultDomainName>\\...), no longer from [initial domain](https://learn.microsoft.com/en-us/microsoft-365/admin/setup/domains-faq?view=o365-worldwide#how-do-i-set-or-change-the-default-domain-in-microsoft-365) (\\\onedrive-\<InitialDomainName>\\...).
  * Possible side effects include:
    * Pinned KONNEKT folders in Quick Access won't work
    * KONNEKT UNC paths in Office apps might still refer to previous names
      {% endhint %}

{% hint style="info" %}
This policy is applicable to KONNEKT version 2.10 and above.
{% endhint %}

To enable this setting, configure it tenant-wide. Enabling this will prompt Azure to register a new app with fewer permissions.

With more detailed permissions, users have to reauthenticate. Additionally, the UNC path and displayed tenant name will switch to the default tenant name rather than the initial tenant name.

This feature enables the use of Conditional Access policies with excluded apps in Microsoft Entra ID.

<figure><img src="/files/BA7YxHVTE0Jy3YusRcch" alt=""><figcaption></figcaption></figure>

### Policy

Policy Name: Enhanced OAuth

Possible values: Can be enabled or disabled.

The default value is disabled.

{% hint style="info" %}
We recommend to use our latest [ADMX template](/configuration/management-options/settings-via-gpo#admx-file) to configure this setting. You will find the policy in "System settings" in GPO editor.
{% endhint %}

{% hint style="info" %}
After the new Azure app registration is set up, the old one should be deleted.
{% endhint %}

### Registry

Key name: EnhancedOAuth

Type: REG\_DWORD 32 bit

| Function |           Value          | Behavior                                               |
| :------: | :----------------------: | ------------------------------------------------------ |
|  Disable | <p>0</p><p>(default)</p> | KONNEKT will use the traditional OAuth 2.0 procedures. |
|  Enable  |             1            | KONNEKT will use an improved OAuth 2.0 code with.      |

The default value is 0 (disable).


# Link scope

### Default SharePoint link scope policy

Select the default link scope for links created on SharePoint files, value can be:

* **0:** Default company setting (Default)
* **1:** Anonymous
* **2:** Organization
* **3:** Disabled

<figure><img src="/files/nTVcigu5ha6mp4P6nkwK" alt=""><figcaption></figcaption></figure>

For more information see <https://github.com/OneDrive/onedrive-api-docs/blob/live/docs/rest-api/api/driveitem_createlink.md#scope-types>

{% hint style="warning" %}

#### Links for "specific people" not supported

Please check your "[Default SharePoint link scope policy](https://docs.microsoft.com/en-us/sharepoint/change-default-sharing-link)" setting in SharePoint Online.

<img src="/files/sHLCQCqiQKJ2HrBTPaRJ" alt="" data-size="original">

*Copy Link To Clipboard* in KONNEKT will not work, if the *Default sharing link type* of a SharePoint Site is set to *Specific people* and the KONNEKT *Default SharePoint link scope policy* is not set.

If you have sites with the default sharing link type *Specific people*, we therefore recommend to set this policy in KONNEKT to *Anonymous*, *Organization,* or *Disabled*. The *default company setting* will not work.
{% endhint %}

## **There are several ways to apply the policy:**

* manually by adding the key in the registry under machine or user registry settings
* via GPO, see [settings via GPO](/configuration/management-options/settings-via-gpo)
* pushing policies via Intune, see [settings for Intune Managed Devices](/configuration/management-options/setting-for-intune-managed-devices-1/intune-system-settings#link-scope)

**Policies** stored in:

`HKEY_CURRENT_USER\SOFTWARE\Policies\GlueckKanja\Konnekt`

`HKEY_LOCAL_MACHINE\SOFTWARE\Policies\GlueckKanja\Konnekt`


# Logging

KONNEKT writes the log to `%localappdata%\KONNEKT`. The log consists of up to 6 files, that are rotated, if full:

* client.txt
* client.1.txt
* client.2.txt
* client.3.txt
* client.4.txt
* client.5.txt

`Client.txt` holds the newest and `client.5.txt` the oldest log lines.

The [Log Level](#log-level) setting determines what information is written to to log.

The files will be rotated, if the newest file has reached the [Log Rotation](#log-rotation) size.

## Log Level

{% hint style="info" %}
Available for KONNEKT 2.1 or newer
{% endhint %}

User can change this setting in the preference menu of the UI. If you do the setting by policy, users can not change it anymore.

The default log level is `info`.

**Policy name:** `Logging Level`

![](/files/VEOb2qWfyeFUsbxDqA5K)

<table><thead><tr><th width="232.33333333333331"></th><th></th><th></th></tr></thead><tbody><tr><td><strong>Option</strong></td><td><strong>Value</strong></td><td><strong>Behavior</strong></td></tr><tr><td>No logging</td><td>0</td><td>No logging</td></tr><tr><td>Error</td><td>1</td><td>Only error records will be stored</td></tr><tr><td>Info (default)</td><td>2</td><td>Info and error records will be stored</td></tr><tr><td>Debug</td><td>3</td><td>All log records will be stored</td></tr></tbody></table>

### **There are several ways to apply the policy**

1. Via GPO, see [settings via GPO](/configuration/management-options/settings-via-gpo)
2. Pushing policies via Intune, see [settings for Intune Managed Devices](/configuration/management-options/setting-for-intune-managed-devices-1)
3. Manually by adding the key in the registry

### Manual setting in the registry

{% hint style="info" %}
You do not need this if you use GPO or Intune management
{% endhint %}

* **Value name:** `LogLevel`
* **Value type:** `REG_DWORD`
* **Value data:** `0, 1, 2 or 3` (see table above)
* **Value stored in:**
  * `HKEY_CURRENT_USER\SOFTWARE\Policies\GlueckKanja\Konnekt`\
    or
  * `HKEY_LOCAL_MACHINE\SOFTWARE\Policies\GlueckKanja\Konnekt`

## Log Rotation

{% hint style="warning" %}
Please do not use this setting unless requested by our support team.
{% endhint %}

The Log Rotation setting determines the maximum size of one log file. The **default** is 1 MB (1024 \* 1024 = 1.048.576 bits), so that the maximum total size of all 6 log files is 6 MB.

* **Value name:** `LogRotation`
* **Value type:** `REG_DWORD`
* **Value data:** Maximum files size; unit is bits
* **Value stored in:**
  * `HKEY_CURRENT_USER\SOFTWARE\GlueckKanja\Konnekt`


# Office365 Co-Authoring

[Microsoft Office 365 Co-Authoring](https://support.microsoft.com/en-us/office/document-collaboration-and-co-authoring-ee1509b4-1f6e-401e-b04a-782d26f564a4) is a technology, that allows you advanced collaboration with Microsoft Office files. One of the benefits is, that multiple users can work on an co-authoring friendly office file simultaneously.

## Setting in KONNEKT

KONNEKT can leverage Microsoft Office 365 Co-Authoring, when opening files from Windows File Explorer. In this case, KONNEKT just hands over the SharePoint URL of a file to the corresponding Microsoft 365 App (Microsoft Word, Excel and PowerPoint). The App will then load the file directly from SharePoint Online.

{% hint style="info" %}
This setting will affect Office files, that are opened from **Windows File Explorer**, only.

Other use-cases (e.g. KONNEKT file is opened from Office App) are not covered and Co-Authoring & Auto-Save will not work.
{% endhint %}

We recommend using Microsoft Office 365 Co-Authoring, since it has valuable benefits. This is why Co-Authoring is activated by default in KONNEKT.

{% hint style="info" %}
Microsoft supports Co-Authoring is not supported for password protected files. [Best Practices for Co-Authoring](https://support.microsoft.com/en-us/office/best-practices-for-coauthoring-in-excel-7564b417-977b-48f1-aa31-98a95bad4dc7)

Instead use [sensitivity labeling](https://learn.microsoft.com/en-us/purview/sensitivity-labels-coauthoring) to keep information safe.
{% endhint %}

However, if you do not want to use Co-Authoring and want to load office files through KONNEKT instead, you can use this setting and deactivate it.

Here are the possible settings:

{% hint style="info" %}
"Browser" function added since KONNEKT version 2.12.0. Usable via ADMX / ADML files.
{% endhint %}

|   Function   | Value | Behavior                                                                                                                                                                                                                      |
| :----------: | :---: | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|    Disable   |   0   | <p>KONNEKT handles up- and downloads to SharePoint Online for Microsoft Offices files.</p><p>Files are opened exclusively - Office 365 Co-Authoring is <strong>not</strong> working.</p>                                      |
| Desktop Apps |   1   | <p>KONNEKT will delegate the file-handling to the Microsoft Office apps for KONNEKT files that are opened from Windows File Explorer.</p><p>Microsoft Office 365 Co-Authoring and Auto-Save is available for those files.</p> |
|    Browser   |   2   | Opens files in the default browser using Office Online.                                                                                                                                                                       |

### GUI

You can find this setting in the preferences menu:

![](/files/OYRCupBaXKzEfT4la0am)

### Policy

Policy Name: **Co-Authoring**

Possible values: can be enabled or disabled.

The default value is enabled.

We recommend to use our [ADMX template](/configuration/management-options/settings-via-gpo#admx-file) to configure this setting. You will find the policy in "System settings" in GPO editor.

#### **Usage**

There are several ways to apply the policy:

* via GPO, see [settings via GPO](/configuration/management-options/settings-via-gpo)
* pushing policies via Intune, see [settings for Intune Managed Devices](/configuration/management-options/setting-for-intune-managed-devices-1/intune-system-settings#co-authoring)

**Policies** stored in:

`HKEY_CURRENT_USER\SOFTWARE\Policies\GlueckKanja\Konnekt`

`HKEY_LOCAL_MACHINE\SOFTWARE\Policies\GlueckKanja\Konnekt`


# Offline attribute

Files provided by KONNEKT are marked with the offline attribute (see also [FILE\_ATTRIBUTE\_OFFLINE](https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-fscc/ca28ec38-f155-4768-81d6-4bfeb8586fc9)). This offline attribute signals to other system components like the Windows Explorer that the file is not locally available. This prevents components like preview, search and indexing from accessing the files.

Marking files with the offline attribute therefore saves bandwidth between the KONNEKT client and SharePoint Online. The downside of this is, that no thumbnails or previews (e.g. of pictures) are rendered in Windows Explorer. Sometimes Windows Explorer also shows a grey X on files that are marked offline (see also [Why is there a grey "X" or "brown suitcase" on my files and folders?](/troubleshooting/why-is-there-a-grey-x-on-my-files-and-folders)).

By default, KONNEKT marks all files (besides PDF) as offline. This policy allows to change this behavior.

{% hint style="warning" %}
Disabling the offline attribute for some file types allows the Windows Explorer to show preview information for the files, at the cost of more network traffic and possible slower response times when browsing through directories. It is also increasing the risk of [SharePoint Throttling](/configuration/system-settings/throttling-prevention/sharepoint-throttling-prevention).

Therefore, please disable the offline attribute with care and only for environments that have a good connection to Office 365.
{% endhint %}

## Setting the Offline Attribute for all files

This policy controls if all files handeled by KONNEKT will be marked with the offline attribute.

**GPO Policy Name**: "Offline Attribute"

**Key Name**: `EnableOfflineAttribute` (REG\_DWORD)

**Values**

|          GPO-setting          | Value | Behavior                                                                    |
| :---------------------------: | :---: | --------------------------------------------------------------------------- |
|         Not configured        |  N/A  | All file-types (besides PDF) handeled by KONNEKT will be marked as offline. |
| <p>Enable</p><p>(default)</p> |   1   | All file-types (besides PDF) handeled by KONNEKT will be marked as offline. |
|            Disabled           |   0   | All file-types handeled by KONNEKT will be marked as online.                |

## Exclude dedicated file-types from offline attribute (filter)

{% hint style="info" %}
This policy is applicable to version 2.0 and above
{% endhint %}

This policy controls which file types will **not** be marked with an offline attribute.

**GPO Policy Name**: "Offline Attribute Filter"

**Key Name**: `OfflineAttributeFilter` (REG\_SZ)

**Values**

|   GPO-setting  |                Value               | Behavior                                                                              |
| :------------: | :--------------------------------: | ------------------------------------------------------------------------------------- |
| Not configured |                 N/A                | Only PDF files are excluded from offline attribute.                                   |
|     Enable     |            \<filetypes>            | The specified file-extensions (separated by \| ) are excluded from offline attribute. |
|    Disabled    | <p>N/A</p><p>(Key not present)</p> | Only PDF files are excluded from offline attribute.                                   |

**Example** for \<filetypes>: `pdf|png|jpg|jpeg`

## **There are several ways to apply the policies**

* manually by adding the key in the registry under machine or user registry settings
* via GPO, see [settings via GPO](/configuration/management-options/settings-via-gpo)
* pushing policies via Intune, see [settings for Intune Managed Devices](/configuration/management-options/setting-for-intune-managed-devices-1/intune-system-settings#offline-attribute)

**Policies** stored in:

`HKEY_CURRENT_USER\SOFTWARE\Policies\GlueckKanja\Konnekt`

`HKEY_LOCAL_MACHINE\SOFTWARE\Policies\GlueckKanja\Konnekt`


# Open file size limitations

By default, KONNEKT limits the size of files, that you open on SharePoint or read from SharePoint:

* KONNEKT **will not open** files, that are bigger than 1 GB
* KONNEKT **will open** files in **read-only**, if they are bigger than 500 MB

{% hint style="success" %}
We recommend, to keep these defaults.
{% endhint %}

## Changing the open file size defaults

You can change the thresholds for "open file size" via registry keys. This may be a good idea, if you are restricting the [cache size](/configuration/system-settings/cache-setting).

{% hint style="info" %}
Please be aware, that this is about the file sizes, that KONNEKT is opening/reading **from** SharePoint Online.

It is **not** about the size of files, that you are writing **to** SharePoint Online.
{% endhint %}

{% hint style="danger" %}
Our support team will offer limited support for environments with thresholds, that are larger than the defaults.
{% endhint %}

### **Read-only threshold**

**Value name:** `OneDriveOpenFilesLargerThanReadOnly`\
**Value storage location:** `HKCU\SOFTWARE\GlueckKanja\Konnekt`\
**Value type:** `DWORD`\
**Value unit:** `bytes`

Files which are larger than this size are opened read-only on OneDrive and O365 accounts.

**Default: 512 \* 1024 \* 1024 bytes = 500 MB**

### **Block opening threshold**

**Value name:** `OneDriveDoNotOpenFilesLargerThan`\
**Value storage location:** `HKCU\SOFTWARE\GlueckKanja\Konnekt`\
**Value type:** `DWORD`\
**Value unit:** `bytes`

Do not open files which are larger than this size on OneDrive and O365 accounts.

**Default: 1024 \* 1024 \* 1024 bytes = 1 GB**


# Throttling Prevention

**KONNEKT’s throttling prevention** includes two policies an "[update frequency control](/configuration/system-settings/throttling-prevention/sharepoint-throttling-prevention)" policy and a "[request rate limiting](/configuration/system-settings/throttling-prevention/throttling-prevention-client-side)" policy designed to manage and control the rate at which requests are made to the Microsoft’s GraphAPI, ensuring that the connections to SharePoint Online (SPO) remain stable and perform optimally. These policies are particularly useful in preventing an excessive resource usage and maintaining a smooth user experience.

The usage of Microsoft 365 APIs is subject to limitations in terms of the amount of requests per time, that an application may send. If an application uses more resources, it will be throttled. You can find more on this in the [Microsoft docs](https://learn.microsoft.com/en-us/sharepoint/dev/general-development/how-to-avoid-getting-throttled-or-blocked-in-sharepoint-online).

Since KONNEKT is using Microsoft SharePoint Online REST API and Microsoft Graph API, it may happen, that Microsoft APIs will throttle your KONNEKT usage. If an application is throttled, the corresponding API (e.g. SPO REST API) tells KONNEKT, that it has to wait for a defined amount of time. This starts from some seconds and can grow up to minutes, depending on the usage. Impacts for KONNEKT may be slow browsing through or loading/writing of files. If the throttling grows up to minutes, it will result in error messages that the drive is currently not available.

KONNEKT has several mechanisms to reduce the occurrence of throttling, which are applied automatically.

## Common Scenarios for Throttling Prevention

### **Scenario 1: High Volume Data Uploads or Data Migration**

When a user attempts to upload a large number of files to / or a data migration within SPO within a short period, the device may reach the specified limit.

### **Scenario 2: Intensive Read Operations**

If a user performs intensive read operations, such as querying or searching a large directory (> 1000 items), the device may reach the specified limit.

Examples:

* Using the File Explorer Search in large folders
* Scrolling through folders with numerous graphic or PDF files

### **Scenario 3: Permission Queries**

Since version 2.10 KONNEKT additionally checks permissions per folder and files since these queries consume a higher number of resource units compared to the other operations. The system may reach the specified limit much faster, which can trigger throttling prevention. Permission queries won't be triggered if "[SharePoint Throttling Prevention](/configuration/system-settings/throttling-prevention/sharepoint-throttling-prevention)" is set to 'High'.

{% hint style="warning" %}
In heavy load environments, all measures may not be enough to prevent throttling.

KONNEKT was made for regular office work. If you use high volume files (e.g. video editing, graphics design, CAD) or read/write gigabytes of data, KONNEKT (& SPO) may not be the proper tool of choice.

Please also check our [use-cases](/#use-cases).
{% endhint %}

## **Resource Units**

Each type of GraphAPI request consumes different amounts of resource units:

* Single-item reads: 1 resource unit each
* Write operations and directory queries: 2 resource units each
* Permission queries: 5

For details see:\
<https://learn.microsoft.com/en-us/sharepoint/dev/general-development/how-to-avoid-getting-throttled-or-blocked-in-sharepoint-online>

## How can I prevent throttling?

#### The following circumstances promote throttling:

* Usage of 3rd party tools for SPO backup - especially during working hours
* Use of tools that crawl your whole filesystem (like preview renderer etc.)
* Use of very big folders with >1000 files on the first level of the folder
* Excessive use of File Explorer Search in large Site Collections or Document Libraries

{% hint style="info" %}
Consider the following settings and actions for all users of an M365 tenant without exceptions.
{% endhint %}

#### To avoid throttling:

* Do not run SPO backups during business hours.
* If the File Explorer Search is inevitable: Optimize File Explorer searches, focus on specific folders or sub-folders to limit GraphAPI requests
* Regular Maintenance: Archive or remove outdated files, folders, Document Libraries, and Site Collections.
* Avoid excessive use of File Explorer Search in large Site Collections or Document Libraries
* Do not use any preview renderer for KONNEKT resources. See also [here](/configuration/system-settings/offline-attribute). You can additionally set the [Offline Filter](/configuration/system-settings/offline-attribute#exclude-dedicated-file-types-from-offline-attribute-filter) to the file extension "YYY" (which does not exist), to prevent Windows File Explorer from rendering previews for PDF files.
* Segment your data (not too many files in the first level of a folder).
* Set "[SharePoint Throttling Prevention](/configuration/system-settings/throttling-prevention/sharepoint-throttling-prevention)" Policy to "High" - only recommended until KONNEKT version 2.10.2
* As of version 2.11.0, we recommend enabling "[Client side throttling](/configuration/system-settings/throttling-prevention/throttling-prevention-client-side)" and setting the "[SharePoint Throttling Prevention](/configuration/system-settings/throttling-prevention/sharepoint-throttling-prevention)" policy to "Auto".

When you turn the [KONNEKT logging to "debug"](/configuration/system-settings/logging#log-level), you will see log entries with "`ThrottlingHook: Need to wait Xs before start`" (where X stands for the amount of seconds SPO wants us to wait).

Log entries that contain "`[Sharepoint] UpdateDrives: Skipping volume due to throttling prevention.`" are NOT caused by SharePoint throttling. Those indicate regular operations to prevent throttling - nothing to worry about. ;-)

## **How It Works**

The "[update frequency control](/configuration/system-settings/throttling-prevention/sharepoint-throttling-prevention)" policy limits requests by enhanced refresh cycles e.g. updating the users Site Collections.

The "[request rate limiting](/configuration/system-settings/throttling-prevention/throttling-prevention-client-side)" policy operates by monitoring the number of requests and there corresponding resource units made within a specified time window and applying limits to these requests. This policy, “[Client side throttling](/configuration/system-settings/throttling-prevention/throttling-prevention-client-side)”, includes **soft** and **hard** limits:

* **Soft Limit**:\
  When the soft limit is reached, the system will begin to throttle requests. This means that most operations will be delayed for a short period (e.g., 2 seconds), and the throttling prevention level will switch to HIGH. Some operations, such as opportunistic upload jobs and read-ahead operations, will be postponed until the request amount falls below the soft limit.
* **Hard Limit**:\
  When the hard limit is reached, the system will stop sending any requests. The application will display an error message until the end of the time window is reached.

{% hint style="warning" %}
Use "Hard Limit" only when necessary, as it prevents KONNEKT from accessing communicating to Microsoft's endpoints.
{% endhint %}


# SharePoint throttling prevention

{% hint style="info" %}
This feature is available in KONNEKT 2.2 or newer
{% endhint %}

This policy controls how frequently KONNEKT refreshes SharePoint data. It limits the requests generated by enhanced refresh cycles, for example when updating the site collections a user has access to.

## Policy

You can load this policy in Policy Editor or Intune with our [ADMX](/configuration/management-options/settings-via-gpo#admx-file).

Policy Name (GPO & Intune): `Sharepoint Throttling Prevention`

Available settings:

* `Enabled`
  * `Autodetect` (default)\
    KONNEKT will decide on active measures.
  * `Low`\
    Throttling prevention takes place in case of throttling events, only.
  * `Medium`\
    More data is cached than in Low to prevent unnecessary requests to SharePoint Online.
  * `High`\
    Throttling prevention has the highest priority. Some changes from other clients (e.g. new libraries or new files/folders) may be updated late (up to 24 hours).
* `Disabled`\
  Default Throttling Prevention takes place

{% hint style="warning" %}
SharePoint Online monitors throttling on several levels. From our experience the tenant level is the most important one for KONNEKT.

Because of that, throttling prevention becomes effective, if **ALL** KONNEKT clients in your tenant use the same prevention level. For example: Just setting this policy to "high" on some clients may have no effect at all. Please set all to "high", if you experience throttling while using KONNEKT.
{% endhint %}

## Manual setting in the registry

{% hint style="info" %}
You do not need this, if you use GPO or Intune management.
{% endhint %}

* **Value name:** `SharepointThrottling`
* **Value type:** `REG_DWORD`
* **Value data**
  * `0` => Autodetect (default)
  * `1` => Low
  * `2` => Medium
  * `3` => High
* Value **stored** in:
  * `HKEY_CURRENT_USER\SOFTWARE\Policies\GlueckKanja\Konnekt`\
    or
  * `HKEY_LOCAL_MACHINE\SOFTWARE\Policies\GlueckKanja\Konnekt`


# Throttling prevention (client side)

{% hint style="info" %}
This feature is available in KONNEKT 2.11 or later
{% endhint %}

In addition to the policy "[SharePoint throttling prevention](/configuration/system-settings/throttling-prevention/sharepoint-throttling-prevention)", a KONNEKT client can be actively throttled. This setting applies to folders and files.

## **Soft Limit**

When the soft limit is reached, the client will limit GraphAPI requests by initiating throttling:

* Most operations will be throttled for 2 seconds.
* Throttling prevention level will switch to HIGH

Some operations will be postponed until the request amount falls below the soft limit.

## **Hard Limit**

When the hard limit is reached, the client will stop to send any GraphAPI requests. The KONNEKT app will display an error until the end of the time window is reached.

## **How to Use It**

Administrators can configure this policy by enabling it and set the following parameters:

<table><thead><tr><th width="272">Name</th><th>Default Value</th><th>Description</th></tr></thead><tbody><tr><td>ClientThrottlingTimeWindow</td><td>300</td><td>Duration, in seconds, over which throttling and resource units are measured. (0 disables client side throttling)</td></tr><tr><td>ClientThrottlingSoftLimit</td><td>250</td><td>Number of resource units that trigger the client side soft limit. (0 disables soft limit)</td></tr><tr><td>ClientThrottlingHardLimit</td><td>0</td><td>Number of resource units that trigger the hard limit. (0 disables hard limit)</td></tr></tbody></table>

## Manual setting in the registry

{% hint style="info" %}
You do not need this, if you use GPO or Intune management.
{% endhint %}

The policy consists of two components in the registry:

1. **Value** (activate the feature)
2. **Key with value per mapping** (describe every single mapping)
3. **Value**

* **Value name:** `ClientThrottling`
* **Value type:** `REG_DWORD`
* **Value data:** `1` (to activate the feature)
* Value **stored** in:
  * `HKEY_CURRENT_USER\SOFTWARE\Policies\GlueckKanja\Konnekt`\
    or
  * `HKEY_LOCAL_MACHINE\SOFTWARE\Policies\GlueckKanja\Konnekt`

2. **Key with value per setting -** e.g. `ClientThrottlingTimeWindow`

* **Value name:** `ClientThrottlingTimeWindow`
* **Value type:** `REG_DWORD`
* **Value data:** `300` (duration in seconds)
* Key **stored** in:
  * `HKEY_CURRENT_USER\SOFTWARE\Policies\GlueckKanja\Konnekt`\
    or
  * `HKEY_LOCAL_MACHINE\SOFTWARE\Policies\GlueckKanja\Konnekt`


# Skip Account Wizard

{% hint style="info" %}
Available in KONNEKT 2.2.0 or newer
{% endhint %}

When KONNEKT starts, it automatically deploys KONNEKT for the current user including the setup of an account. With this policy, you can prevent this.

**Policy name:** `SkipAccountWizard`

| Policy Setting     | Behavior                                             |
| ------------------ | ---------------------------------------------------- |
| Disabled (Default) | KONNEKT shall be configured for the current user     |
| Enabled            | KONNEKT shall NOT be configured for the current user |

{% hint style="warning" %}
It is very important to populate this policy **prior** the first start of KONNEKT to be effective.
{% endhint %}

Please see also [here](/troubleshooting/subscribe-a-subset-of-users) for related information on this topic.

### **There are several ways to apply the policy**

1. Via GPO, see [settings via GPO](/configuration/management-options/settings-via-gpo)
2. Pushing policies via Intune, see [settings for Intune Managed Devices](/configuration/management-options/setting-for-intune-managed-devices-1)
3. Manually by adding the key in the registry

### Manual setting in the registry

{% hint style="info" %}
You do not need this if you use GPO or Intune management
{% endhint %}

* **Value name:** `SkipAccountWizard`
* **Value type:** `REG_DWORD`
* **Value data:** `0` or `1`
  * `0` = disabled
  * `1` = enabled
* **Value stored in:**
  * `HKEY_CURRENT_USER\SOFTWARE\Policies\GlueckKanja\Konnekt`


# Update checker

{% hint style="info" %}
Available for KONNEKT 2.1 or newer
{% endhint %}

This policy defines if KONNEKT checks for software updates.

If the policy is enabled, KONNEKT will check for software updates and inform the user via a pop-up window to download the newer version. If the policy is disabled, no update checks take place, which means no pop-up window will show up.

**Policy name:** `Update check`

![](/files/gx3FuegnbBgR7ImGKzmz)

## **There are several ways to apply the policy**

1. Via GPO, see [settings via GPO](/configuration/management-options/settings-via-gpo)
2. Pushing policies via Intune, see [settings for Intune Managed Devices](/configuration/management-options/setting-for-intune-managed-devices-1)
3. Manually by adding the key in the registry

## Manual setting in the registry

{% hint style="info" %}
You do not need this if you use GPO or Intune management
{% endhint %}

* **Value name:** `UpdateInterval`
* **Value type:** `REG_DWORD`
* **Value data:** `78` (Hexadecimal) for enabled, and `0` for disabled
* **Value stored in:**
  * `HKEY_CURRENT_USER\SOFTWARE\Policies\GlueckKanja\Konnekt`\
    or
  * `HKEY_LOCAL_MACHINE\SOFTWARE\Policies\GlueckKanja\Konnekt`


# Other

{% content-ref url="/pages/-M\_U\_qn0qeppXA8JViNV" %}
[Proxy settings](/configuration/other/proxy-settings)
{% endcontent-ref %}

{% content-ref url="/pages/-M\_U\_d4JH7wUna7YEfGr" %}
[Set license key](/configuration/other/license-key-on-multi-user-environments)
{% endcontent-ref %}


# Proxy settings

We highly recommend excluding all traffic to Microsoft 365 from proxy usage. For more details, please have a look at [Microsoft's network connectivity principles](https://docs.microsoft.com/en-us/microsoft-365/enterprise/microsoft-365-network-connectivity-principles?view=o365-worldwide).

However, KONNEKT is using the proxy settings of the Windows OS. If a proxy server is set, KONNEKT will use this proxy server.

In detail, KONNEKT calls [`WinHttpGetProxyForUrl`](https://docs.microsoft.com/en-us/windows/win32/api/winhttp/nf-winhttp-winhttpgetproxyforurl) with the URI `https://graph.microsoft.com` to examine, if a proxy must be used.

{% hint style="success" %}
To bypass your proxy server with traffic from KONNEKT, please make sure, that Windows OS will exclude the URI `https://graph.microsoft.com` from proxy usage.

You may do this by putting this URI on the exclude list in your proxy PAC file.

You should also make sure, that the KONNEKT client can reach [Microsoft Entra ID and SharePoint Online](https://docs.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges?view=o365-worldwide) without being interfered by proxy servers or other application layer gateways (ALG).
{% endhint %}

{% hint style="warning" %}
KONNEKT can use proxy servers. However, we offer limited support for clients that are experiencing network connectivity-related issues while connecting to Microsoft 365 via proxy server or other application layer gateways (ALG).
{% endhint %}


# Set license key

## License Key Storage

KONNEKT searches for license keys in two registry keys:

`HKEY_CURRENT_USER\SOFTWARE\GlueckKanja\Konnekt\License` (REG SZ)

`HKEY_LOCAL_MACHINE\SOFTWARE\GlueckKanja\Konnekt\License` (REG SZ)

{% hint style="info" %}
If a license key is set at machine level (HKLM), it will supersede a license key at user level (HKCU).
{% endhint %}

## License Key Configuration

There are several options how you can configure the license key:

|         Option        |                                                                Description                                                                |                                                                          Use Case                                                                         | Lic Key Storage Location |
| :-------------------: | :---------------------------------------------------------------------------------------------------------------------------------------: | :-------------------------------------------------------------------------------------------------------------------------------------------------------: | :----------------------: |
| **Interactive Setup** |                                                 Enter the key during the interactive setup                                                |                                                  This option may be a good choice for a singular system.                                                  |           HKLM           |
|       **Policy**      |                                               Set the license key via GPO or Intune policy.                                               | <p>This is the recommended approach for managed environments.<br>See <a href="#set-license-key-via-registry-gpo-mdm">Set License Key</a> for details.</p> |       HKLM or HKCU       |
|   **MSI Parameter**   | <p>Sets the license key as a MSI-parameter<br>(e.g. with silent <a href="/pages/-Manwi3yO7f-RwKgSMwV#silent-installation">Setup</a>).</p> |                                    This option may be a good choice for environments with a software deployment system.                                   |           HKLM           |
|  **Preferences Menu** |                                               Enter the license key in the preferences menu.                                              |                                                   This option may be used for single user systems, only.                                                  |           HKCU           |

Entering the license key in the preferences menu:

![](/files/OsygsmRcCH3JycUyey4V)

{% hint style="danger" %}
The preference menu sets the license for the current user (HKCU), only. Other users logging into the same machine would also have to set the license.

If a license key is configured at HKLM, settings via preferences menu are not effective. (see [Set License Key](#license-key-storage) for details).
{% endhint %}

## Set License Key via Registry/GPO/MDM

Key name: **License**\
Type: REG\_SZ (String Value).

Sets the license key.

We recommend to use our [ADMX template](/configuration/management-options/settings-via-gpo#admx-file) to configure this setting.

## **There are several ways to apply the policy:**

* manually by adding the key in the registry under machine or user registry settings
* via GPO, see [settings via GPO](/configuration/management-options/settings-via-gpo)
* pushing policies via Intune, see [settings for Intune Managed Devices](/configuration/management-options/setting-for-intune-managed-devices-1/intune-other-settings#set-license-key)

**Policies** stored in:

`HKEY_CURRENT_USER\SOFTWARE\Policies\GlueckKanja\Konnekt`

`HKEY_LOCAL_MACHINE\SOFTWARE\Policies\GlueckKanja\Konnekt`


# Troubleshooting

Start here when something isn't working. Follow these steps to identify your issue and jump to the relevant resolution page.

## Before you start

If **multiple users report the same issue at the same time**, or if KONNEKT debug logs show Graph API errors (HTTP 429, 500, 503, 504, or `UnknownError`), the root cause may be on the Microsoft 365 backend rather than in KONNEKT. Confirm this first: [Reproduce file issues with Graph Explorer](https://docs.konnekt.io/troubleshooting/reproduce-file-issues-with-graph-explorer).

## What's the problem?

### KONNEKT drives or shares are not visible

1. **Is KONNEKT installed?**
   * Check: `Get-WmiObject -Class Win32_Product | Where-Object { $_.Name -like "*Konnekt*" }`
   * Not installed → [Install KONNEKT](https://docs.konnekt.io/installation/setup)
   * On ARM64 devices, make sure you installed the ARM64 version. An x64 install on ARM64 will appear successful but the driver will fail to load. → [Failed to open Device](https://docs.konnekt.io/troubleshooting/failed-to-open-device)
2. **Has the device been rebooted after installation?**
   * KONNEKT requires a reboot to load its kernel-mode driver. Reboot and check again.
3. **Is the KONNEKT service running?**
   * Check: `Get-Service -Name "Konnekt*"`
   * Not running → restart the service or reinstall.
4. **Is the user signed in?**
   * Right-click the KONNEKT tray icon → **Accounts**. If no account is listed, sign in.
   * "Admin approval required" → [Grant tenant-wide admin consent](https://docs.konnekt.io/installation/security/grant-admin-consent-in-enterprise-applications)
5. **Drive or share is visible but clicking does nothing?**
   * → [Clicking a share does nothing](https://docs.konnekt.io/troubleshooting/clicking-a-share-does-nothing)

### Sites or libraries are missing

1. **Using auto-mapping?**
   * Check that `O365SharepointUsage = 1` in the registry.
   * Verify the user has access to the site in the SharePoint web interface.
   * Check the KQL site query - a restrictive query may exclude the site. See [Auto mapping](https://docs.konnekt.io/configuration/mappings/auto-mapping).
   * Verify the user's Microsoft Entra ID group membership if sites are filtered by group.
   * Site owner but not member? KONNEKT's discovery only finds sites the user is a **member** of. → [Some sites or libraries do not appear in KONNEKT](https://docs.konnekt.io/troubleshooting/causes-of-missing-content/some-sites-or-libraries-do-not-appear-in-konnekt)
2. **Using managed mappings?**
   * Check that the `SharepointSites` policy is applied: `gpresult /r` or check the registry.
   * Verify the SharePoint URL in the policy is correct and accessible.
3. **Trying to add a share manually and getting "Failed to open site: Key not found"?**
   * → [Add Share: "Key not found"](https://docs.konnekt.io/troubleshooting/add-share-key-not-found)
4. **Site exists in SharePoint but not in KONNEKT?**
   * The user may lack permission to the site. Test access via the SharePoint web interface.
   * The site type may not match the KQL query (for example, personal OneDrive sites are not discovered by the default query).

→ [Sites missing or folders empty](https://docs.konnekt.io/troubleshooting/causes-of-missing-content/sites-missing-or-folders-empty) | [Some sites or libraries do not appear](https://docs.konnekt.io/troubleshooting/causes-of-missing-content/some-sites-or-libraries-do-not-appear-in-konnekt)

### Folders are empty

1. **All libraries empty?**
   * Admin consent may not be granted, or the API permissions may be incomplete.
   * → [Grant tenant-wide admin consent](https://docs.konnekt.io/installation/security/grant-admin-consent-in-enterprise-applications)
   * → [Empty libraries](https://docs.konnekt.io/troubleshooting/causes-of-missing-content/empty-libraries)
2. **Specific library empty?**
   * The user may not have permission to the library's content. Check SharePoint permissions.
   * The library may genuinely be empty.
3. **Managed mapping shows an empty folder?**
   * The site URL in the policy may be incorrect. Verify it by opening the URL in a browser.

→ [Empty libraries](https://docs.konnekt.io/troubleshooting/causes-of-missing-content/empty-libraries) | [Sites missing or folders empty](https://docs.konnekt.io/troubleshooting/causes-of-missing-content/sites-missing-or-folders-empty)

### Authentication errors

1. **"Failed to obtain access token"**
   * → [Access token issues](https://docs.konnekt.io/troubleshooting/access-token-issues)
2. **MFA prompt loop (repeated MFA prompts)**
   * Conditional Access policy conflict or WAM broker issue.
   * → [Conditional Access](https://docs.konnekt.io/installation/security/conditional-access)
3. **Wrong account signed in**
   * Right-click tray icon → **Accounts** → remove the wrong account → add the correct one.
4. **"Admin approval required"**
   * → [Grant tenant-wide admin consent](https://docs.konnekt.io/installation/security/grant-admin-consent-in-enterprise-applications)

→ [Access token issues](https://docs.konnekt.io/troubleshooting/access-token-issues)

### File operation errors

1. **Upload failed**
   * Check the error details via tray icon → **Errors**.
   * Verify network connectivity.
   * Check if SharePoint throttling is occurring (look for HTTP 429 in debug logs). If you see throttling or backend errors, [reproduce with Graph Explorer](https://docs.konnekt.io/troubleshooting/reproduce-file-issues-with-graph-explorer) to confirm Microsoft-side issues.
   * → [How to deal with error(s)](https://docs.konnekt.io/troubleshooting/how-to-deal-with-error-s)
2. **File locked / read-only unexpectedly**
   * Another user may have the file open without co-authoring enabled.
   * File may exceed the read-only size threshold. → [Open file size limitations](https://docs.konnekt.io/configuration/system-settings/open-file-size-limitations)
3. **Permission denied**
   * The user lacks write permission in SharePoint. Verify via the web interface.
4. **"Path too long" or filename errors**
   * Check path and filename length against the limits. → [What is the maximum path and file name length?](https://docs.konnekt.io/troubleshooting/what-is-the-maximum-path-and-file-name-length)

→ [How to deal with error(s)](https://docs.konnekt.io/troubleshooting/how-to-deal-with-error-s)

### Opening Office files fails

1. **Office shows a warning on open ("could harm your computer")**
   * Mark of the Web (MOTW) is applied to files from network locations. → [Opening MS Office documents display a warning message](https://docs.konnekt.io/troubleshooting/opening-ms-office-documents-displays-a-warning-message)
   * Often resolved by adding KONNEKT paths to trusted sites. → [Add KONNEKT paths as Trusted sites](https://docs.konnekt.io/troubleshooting/add-konnekt-paths-as-trusted-sites)
2. **Double-clicking an Office file does nothing or Excel macro files won't open**
   * KONNEKT paths need to be in the Trusted Sites zone. → [Add KONNEKT paths as Trusted sites](https://docs.konnekt.io/troubleshooting/add-konnekt-paths-as-trusted-sites)
3. **KONNEKT crashes when opening or previewing Office files**
   * Attack Surface Reduction (ASR) rules may be blocking KONNEKT. Exclude `Konnekt.exe` and `KonnektStarter.exe` from the "Office Child Process" ASR rule. → [Risky action blocked](https://docs.konnekt.io/troubleshooting/risky-action-blocked)
4. **Office shows an outdated version of a file**
   * → [Office shows outdated versions](https://docs.konnekt.io/troubleshooting/office-shows-outdated-versions)

### Performance issues

1. **Slow folder browsing**
   * Check item count in the folder (>1,000 items slows browsing).
   * Check cache settings - a very low TTL causes more API calls.
   * If slowness correlates with Graph API 429 or 5xx errors in the debug log, [reproduce with Graph Explorer](https://docs.konnekt.io/troubleshooting/reproduce-file-issues-with-graph-explorer) to confirm throttling or backend issues.
2. **Slow file open**
   * Check file size and network bandwidth.
   * Check for throttling (HTTP 429 in logs). If present, [reproduce with Graph Explorer](https://docs.konnekt.io/troubleshooting/reproduce-file-issues-with-graph-explorer).
3. **Intermittent slowness (especially mornings)**
   * Likely antivirus scanning KONNEKT drives.
   * → [Slow performance or errors caused by antivirus scanning](https://docs.konnekt.io/troubleshooting/slow-performance-or-errors-caused-by-antivirus-scanning)

### Other issues

| Issue                           | Resolution                                                                                                                                                                                                                                 |
| ------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| PDF preview broken (Windows 11) | → [PDF preview broken after Windows 11 update](https://docs.konnekt.io/troubleshooting/pdf-preview-broken-after-windows-11-update)                                                                                                         |
| Grey X on files                 | Expected behavior - KONNEKT marks files as `FILE_ATTRIBUTE_OFFLINE` to save bandwidth. Not an error. See [Why is there a grey X or brown suitcase](https://docs.konnekt.io/troubleshooting/why-is-there-a-grey-x-on-my-files-and-folders). |
| Brown suitcase overlay on files | File is marked for offline use. Expected behavior.                                                                                                                                                                                         |
| KONNEKT tray icon missing       | Reboot the device. If still missing, reinstall KONNEKT.                                                                                                                                                                                    |
| Can't resolve the issue         | → [Prepare debug logs](https://docs.konnekt.io/troubleshooting/debug-log-preparation) and [contact support](https://docs.konnekt.io/support)                                                                                               |

## Related pages

* [Reproduce file issues with Graph Explorer](https://docs.konnekt.io/troubleshooting/reproduce-file-issues-with-graph-explorer) - isolate KONNEKT issues from Microsoft 365 backend issues
* [Changelog](https://docs.konnekt.io/changelog) - recent fixes and resolved issues
* [Debug log preparation](https://docs.konnekt.io/troubleshooting/debug-log-preparation) - how to collect logs for support
* [Support](https://docs.konnekt.io/support) - how to reach KONNEKT support


# Administrative tasks

Procedural guides for common KONNEKT administrative tasks. If you're trying to diagnose something that isn't working, start at the [Troubleshooting decision tree](https://docs.konnekt.io/troubleshooting) instead.

## Account and tenant management

* [Change the tenant name](https://docs.konnekt.io/troubleshooting/how-to-change-the-tenant-name) - switch from the initial tenant name to the default domain name (relevant for KONNEKT 2.9.1 and earlier)
* [Subscribe a subset of users](https://docs.konnekt.io/troubleshooting/subscribe-a-subset-of-users) - limit KONNEKT access to specific users within a tenant

## Removal

* [Manual uninstallation](https://docs.konnekt.io/troubleshooting/manual-uninstallation) - remove KONNEKT when the standard uninstaller doesn't work

## Related procedures in other sections

Procedures that live elsewhere in the docs but are often needed:

### Installation and setup

* [Install KONNEKT](https://docs.konnekt.io/installation/setup) - interactive and silent installation
* [Configure the Microsoft 365 account](https://docs.konnekt.io/installation/configure-office-365-account) - connect KONNEKT to the user's account
* [Software updates](https://docs.konnekt.io/installation/software-updates) - keeping KONNEKT up to date

### Security and permissions

* [Grant tenant-wide admin consent](https://docs.konnekt.io/installation/security/grant-admin-consent-in-enterprise-applications) - consent to KONNEKT's required permissions
* [Configure Conditional Access](https://docs.konnekt.io/installation/security/conditional-access) - KONNEKT behavior with Entra ID Conditional Access policies
* [Add KONNEKT paths as Trusted sites](https://docs.konnekt.io/troubleshooting/add-konnekt-paths-as-trusted-sites) - required for Office files to open via double-click

### Support and diagnostics

* [Prepare debug logs](https://docs.konnekt.io/troubleshooting/debug-log-preparation) - collect logs for support cases
* [Reproduce file issues with Graph Explorer](https://docs.konnekt.io/troubleshooting/reproduce-file-issues-with-graph-explorer) - isolate KONNEKT issues from Microsoft 365 backend issues

## Related pages

* [Troubleshooting decision tree](https://docs.konnekt.io/troubleshooting) - diagnose a specific issue
* [Changelog](https://docs.konnekt.io/changelog) - release history and recent fixes
* [Support](https://docs.konnekt.io/support) - how to reach KONNEKT support


# Access token issues

Authentication token errors are the most common KONNEKT issues. The pages below cover specific error messages and their solutions.

1. [Error message about missing token](/troubleshooting/access-token-issues/error-message-about-missing-token)\
   Admin consent for the KONNEKT app registration is missing, was revoked, or has not been granted for the required scopes in Microsoft Entra ID. This is the typical cause at initial rollout and after tenant-wide consent resets.
2. [Failed to obtain access token](/troubleshooting/access-token-issues/failed-to-obtain-access-token)\
   The user's sign-in fails before a token is issued, usually because a Conditional Access policy (most often MFA) cannot be satisfied without a Primary Refresh Token (PRT) on the device.
3. [Failed to obtain access token to your OneDrive account](/troubleshooting/access-token-issues/failed-to-obtain-access-token-to-your-onedrive-account)\
   The OneDrive-specific token request fails while other sign-ins succeed. Start by checking the interactive and non-interactive sign-in logs in Microsoft Entra ID for the affected user.

If none of these resolve the issue, prepare a [debug log](/troubleshooting/debug-log-preparation) and open a support ticket.

### Related pages

* [Conditional Access](/installation/security/conditional-access)
* [Debug log preparation](/troubleshooting/debug-log-preparation)


# Error message about missing token

If you see an error regarding a missing token (like the one below) please re-check the consent for **KONNEKT**.

![](/files/-MA69eBtJgEIt0yPxuhZ)

You can consent **KONNEKT** permissions in two ways:

**1-** Directly after the installation, a Microsoft Pop-up window shows up, log on with a Microsoft Entra ID admin account (or one account has a role that allows granting admin consent), check the option **"Consent on behalf of your organization"** and grant **KONNEKT** needed permissions.

<figure><img src="/files/pIhR7BJhPDmhX2Lob5Dm" alt=""><figcaption></figcaption></figure>

**2-** From **Azure Portal**, you can check the permissions granted to KONNEKT, edit, or delete it. Therefore please check [Granting tenant-wide admin consent](/installation/security/grant-admin-consent-in-enterprise-applications)


# Failed to obtain access token to your OneDrive account

{% hint style="info" %}
Can appear in KONNEKT 2.9.0 and higher.
{% endhint %}

### Problem

When trying to log in to KONNEKT, the error message "Failed to obtain an access token to your OneDrive account" appears.

<figure><img src="/files/bDmqiM0DMmMLtKs9d021" alt=""><figcaption></figcaption></figure>

### Cause

If you see this error, please check the sign-in logs in Microsoft Entra ID to see if there are any failed sign-ins.

Take a look at the active and interactive Sign-ins.

<figure><img src="/files/pUzDT6WuIYDUQeKEegs2" alt=""><figcaption></figcaption></figure>

Check the "Device info" under Activity Details: Sign-ins

<figure><img src="/files/gSj7d4Zi9XOloTFS7ziU" alt=""><figcaption></figcaption></figure>

### Solution

This issue can be solved by changing the [browser engine](/configuration/system-settings/authentication-browser-engine) to authenticate the user.


# Failed to obtain access token

## Problem

When you are trying to log in to KONNEKT you get the error message "Failed to obtain access token".

## Cause

KONNEKT does not support having "Excluded Apps" in an MFA-requiring Microsoft Entra ID Conditional Access policy in combination with a non-SSO Windows session.

## Workaround

Our recommended workaround is to enable the Windows machine for holding a Primary Refresh Token (PRT), e.g. by making the device Microsoft Entra joined or Microsoft Entra registered. Please see [here ](https://learn.microsoft.com/en-us/entra/identity/devices/concept-primary-refresh-token#how-is-a-prt-issued)for details.

Other alternatives are (not really recommended):

* Remove MFA requirement from the corresponding Conditional Access Policy. To keep some security for CA policies without MFA, you could enforce [Trusted Locations (e.g. public IP addresses of your VDI hosts)](https://learn.microsoft.com/en-us/entra/identity/conditional-access/location-condition)

or

* use a Conditional Access Policy without "Excluded Apps". Please also see [Conditional Access configuration](/installation/security/conditional-access).

## Solution

A solution was implemented in KONNEKT version 2.10 - "[Enhanced OAuth](/configuration/system-settings/enhanced-authentication)".


# Add KONNEKT paths as Trusted sites

## Situation

Users cannot open files e.g. Excel macro files by double clicking on it in KONNEKT.

## Problem

All SharePoint URLs and the corresponding UNC path used in KONNEKT need to be set as trusted sites

## Solution

These can be set in:

* Internet options in Edge or Internet Explorer (for Windows 10 users)
* Trust Center in an Office app of your choice
* Or via an Intune policy

### Intune

* Create new profile for "Windows 10 and later"
* Profile type "Settings catalog"

<figure><img src="/files/CVOeqEVWZlYBNsFJ8z8y" alt=""><figcaption></figcaption></figure>

* Search for "security pages"
* Select the following category \\

```
Windows Components > Internet Explorer > Internet Control Panel > Security Page
```

* Use either
  * Site to Zone Assignment List
  * Site to Zone Assignment List (User)

<figure><img src="/files/RZhjUHJ2WPAaTALijtf0" alt=""><figcaption></figcaption></figure>

* Set all three paths - UNC and URL

<figure><img src="/files/dCdgqeuFczPozHizXZJy" alt=""><figcaption></figcaption></figure>

```
"<TenantName>.sharepoint.com"      = "2",
"<TenantName>-my.sharepoint.com"   = "2",
"\\OneDrive-<TenantName>" = "2"​
```

{% hint style="info" %}
TenantName is defined by the initial or the default tenant name set in[ Microsoft's Admin Center](https://admin.cloud.microsoft/?#/Domains). This depends if "[EnhancedAuthentication](/configuration/system-settings/enhanced-authentication)" is enabled.
{% endhint %}

Setting this up won't pretend Outlook from displaying a Security notice.

<figure><img src="/files/l1hWW2tKVN3fFPQyhZBL" alt=""><figcaption></figcaption></figure>

For instructions on how to turn off this dialog, refer to the article [*Enable or Disable Hyperlink Warning Messages in Office Programs*](https://learn.microsoft.com/en-us/troubleshoot/microsoft-365-apps/office-suite-issues/enable-disable-hyperlink-warning#how-to-globally-enable-or-disable-hyperlink-warnings).

HKEY\_CURRENT\_USER\software\policies\microsoft\office\16.0\common\security\
DWORD: DisableHyperlinkWarning\
Value: 1

{% hint style="warning" %}
This workaround makes a computer or a network more vulnerable to attack by malicious users or by malicious software such as viruses.
{% endhint %}


# Add Share: "Key not found"

### Problem

When you try to add a SharePoint library manually (see [Additional document libraries](/configuration/mappings/add-a-document-library#add-additional-document-libraries)), you get the the error message "Failed to open site: Key not found".

![Error-Message: "Failed to open site: Key not found"](/files/4UZnAkIknTQjexmoKw9H)

Customers with this issue may also also experience this: [All libraries are empty](/troubleshooting/causes-of-missing-content/empty-libraries/libraries-are-empty)

### Background

Microsoft (temporarily) changed the content of the response of the query for the library discovery for some tenants. Therefore KONNEKT will not map those affected libraries.

### Solution

We implemented a workaround for that behavior starting with KONNEKT V2.0.0. Please see here, how to get the update: [Software updates](/installation/software-updates).


# Causes of missing content

There are several reasons that might cause missing Site Collections, Document Libraries, or empty folders. The following articles are sorted from newest to oldest appearance.


# Empty libraries


# Empty document libraries for managed mappings

## Situation

Currently, some customers are experiencing issues where Document Libraries don't show any content for volumes that were mapped by managed mappings. Permissions for these users didn't change and are displayed properly via the Edge browser.

KONNEKT uses the GraphAPI to get these data from SharePoint Online. The query responsible for this can be located in the KONNEKT logs preceding this line:

```
[RESTkitClient] Http request (OneDriveClient::GetItemByPath) GET:
```

The structure is similar to this:

```
https://graph.microsoft.com/v1.0/sites/TenantName.sharepoint.com:/sites/SiteName:/drive/root?$select=name
```

Issue in the [Microsoft SharePoint Github repo](https://github.com/SharePoint/sp-dev-docs/issues/10313).

## **Solution**

Please upgrade to [KONNEKT 2.11.2](https://docs.konnekt.io/troubleshooting/causes-of-missing-content/empty-libraries/pages/-M8zM0M0y-TYoiZ5JFE-#id-2.11.2-published-2025-08-04) or later.

We added a mitigation in KONNEKT 2.11.2 that does not use the affected Graph API calls.


# Empty default libraries - error 404

## Problem

All document libraries in KONNEKT and mapped drives are empty.

## Background

There are glitches in certain data centers hosting SharePoint Online on Microsoft's site. KONNEKT uses Microsoft's GraphAPI to access all information related to document libraries and their content.

Especially the request to get the default document library from a Site Collection ([Get drive](https://learn.microsoft.com/en-us/graph/api/drive-get)). KONNEKT's logs should contain entries if the default library operations fail:

```
[2025-05-07 11:31:28.957] [30304] [error] [RESTkitClient] Http request (OneDriveClient::GetDefaultDrive) GET: https://graph.microsoft.com/v1.0/sites/<TenantName>.sharepoint.com,8fd7d761-4f99-4fdc-a0aa-de6b685e5306,56d1fa73-2339-4329-9df3-61100d751650/drive - 404
    error: Item not found: The resource could not be found.(404)
   "{"error":{"code":"itemNotFound","message":"The resource could not be found.","innerError":{"date":"2025-05-07T09:31:28","request-id":"17a44641-4204-4811-b176-58a379125b5d","client-request-id":"17a44641-4204-4811-b176-58a379125b5d"}}}"
    Response Header:
Cache-Control: no-store, no-cache
client-request-id: 17a44641-4204-4811-b176-58a379125b5d
Content-Type: application/json
Date: Wed, 07 May 2025 09:31:27 GMT
request-id: 17a44641-4204-4811-b176-58a379125b5d
Strict-Transport-Security: max-age=31536000
Transfer-Encoding: chunked
x-ms-ags-diagnostic: {"ServerInfo":{"DataCenter":"France Central","Slice":"E","Ring":"5","ScaleUnit":"004","RoleInstance":"PA2PEPF00011C65"}}
    Response:
{"error":{"code":"itemNotFound","message":"The resource could not be found.","innerError":{"date":"2025-05-07T09:31:28","request-id":"17a44641-4204-4811-b176-58a379125b5d","client-request-id":"17a44641-4204-4811-b176-58a379125b5d"}}}
```

or

```
[2025-05-09 08:43:36.353] [23796] [error] [RESTkitClient] Http request (OneDriveClient::GetDefaultDrive) GET: https://graph.microsoft.com/v1.0/sites/<TenantName>.sharepoint.com,8fd7d761-4f99-4fdc-a0aa-de6b685e5306,56d1fa73-2339-4329-9df3-61100d751650/drive - 404
    error: Item not found: The resource could not be found.(404)
   "{"error":{"code":"itemNotFound","message":"The resource could not be found.","innerError":{"date":"2025-05-09T06:43:36","request-id":"17a44641-4204-4811-b176-58a379125b5d","client-request-id":"17a44641-4204-4811-b176-58a379125b5d"}}}"
```

To investigate, use GraphExplorer to check the get request for this document library:

<https://developer.microsoft.com/en-us/graph/graph-explorer>

## Workarounds

1\) Enable the setting "[Add all SharePoint document libraries](https://docs.konnekt.io/configuration/mappings/auto-mapping#map-all-document-libraries)".

If enabled KONNEKT will use the [List drives](https://learn.microsoft.com/en-us/graph/api/drive-list?view=graph-rest-1.0\&tabs=http) request to retrieve all document libraries from Site Collections.

{% hint style="info" %}
Please be aware that enabling this setting will cause existing file links to break.
{% endhint %}

2\) Use "[Managed Mappings](/configuration/mappings/managed-mappings)" to map the important document libraries and disable the setting "[Sharepoint Sites Autodiscovery](https://docs.konnekt.io/configuration/mappings/auto-mapping#map-all-document-libraries)".

## GitHub issue

<https://github.com/SharePoint/sp-dev-docs/issues/10241>


# All libraries are empty

## Problem

Some or all libraries in KONNEKT and mapped drives are empty.

KONNEKT client log shows the following messages: `[Sharepoint] Failed to determine drives of site ... Key not found. Use default drive instead.`

Customers with this issue may also also experience this: [Add Share: "Key not found"](/troubleshooting/add-share-key-not-found)

## Background

Microsoft (temporarily) changed the content of the response of the query for the library discovery for some tenants. Therefore KONNEKT will not map those affected libraries.

This only happens if the feature "Automatically add all SharePoint document libraries" (see [Auto mapping](/configuration/mappings/auto-mapping#map-all-document-libraries)) is used.

## Solution

We implemented a workaround for that behavior starting with KONNNEKT V2.0.0. Please see here, how to get the update: [Software updates](/installation/software-updates).

After installing the new version of KONNEKT, please

* Reboot the machine,
* Start Windows Explorer and click on KONNEKT node,
* Wait 5-10 minutes.

After this procedure, the libraries should work.

## Similar Problems

Please also check this page: [Sites missing or folders empty](/troubleshooting/causes-of-missing-content/sites-missing-or-folders-empty)


# Site Collections are not displayed for some users

## Situation

Currently, some customers are experiencing issues where specific users cannot view any Site Collections within KONNEKT.

KONNEKT uses the RestAPI connected to SharePoint Online to identify the Site Collections a user can access. The query responsible for this can be located in the KONNEKT logs preceding this line:

```
Sharepoint query returned the folloing sites 
```

The structure is similar to this:

```
https://<TenantName>.sharepoint.com/_api/search/query?QueryText=%27%28webtemplate%3ASTS%20OR%20webtemplate%3AGROUP%20OR%20webtemplate%3ASITEPAGEPUBLISHING%29%20AND%20%28contentclass%3DSTS_Site%20OR%20contentclass%3DSTS_Web%29%20AND%20path%3Ahttps%3A%2F%2F%27&SelectProperties=%27SiteId%2CSiteLogo%2CPath%2CTitle%2CDescription%27&Properties=%27EnableMultiGeoSearch%3Atrue%2C%20EnableDynamicGroups%3Atrue%27&ClientType=%27KONNEKT%27&StartRow=0&RowLimit=500&BypassResultTypes=true&EnableQueryRules=false&ProcessBestBets=false&ProcessPersonalFavorites=false&TrimDuplicates=false
```

When using Edge, the XML should display all Site Collections that a user can access. At the end, the "InternalRequestId" will be provided, which can assist Microsoft in identifying the issue's root cause.

## **Temporary workaround to add shares**

\- ​Manually

\- Right click on Accounts / Add Share

![](https://eucattachment.freshdesk.com/inline/attachment?token=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpZCI6MjA0MDA2MTY3MTUzLCJkb21haW4iOiJjNGE4LmZyZXNoZGVzay5jb20iLCJhY2NvdW50X2lkIjozNDEwODY3fQ.EwKt8cWoK0Xa0306p3SGU4SYjphP1T-lB3LReg8fZG0)

\
\- or use "[Managed Mappings](/configuration/mappings/managed-mappings)"\
\
\
Please help to raise the awareness by opening a Microsoft for the affected M365 tenant.

```
"The following RestAPI query returns site collections for some users and no site collections for others. Nothing has been changed in the corresponding authorizations. This is the corresponding request:"
```

## GitHub issue

{% @github-files/github-code-block url="<https://github.com/SharePoint/sp-dev-docs/issues/10256>" %}

## Issue solved

<https://admin.microsoft.com/#/servicehealth/history/:/alerts/SP1072852>


# Sites missing or folders empty

## Problem

Some sites are not shown in the KONNEKT node.\
or

Some folders of mapped sites/libraries are empty.

## Cause

Currently we see more and more error responses (e.g. 500) for proper requests to SharePoint Online Search. Sometimes the site discovery of KONNEKT is affected by this.

In some cases/tenants, SharePoint Online does permanently fail to search at all. If this is the case, KONNEKT will not work properly.

## Check if your tenant is affected

You can check if your tenant is affected, by calling this site multiple times at different times at the day:

`https://<YourTenant>.sharepoint.com/_layouts/15/osssearchresults.aspx`

If you see a result like this frequently, please open a ticket at Microsoft:

![](/files/EGlgsFJtEt1d1qYhogSn)

## Solution

We made KONNEKT more robust to failures of SharePoint Online Search. This applies to the following KONNEKT releases:

* 2.1.0 - 2.2.1
* 2.6.0 or newer

If the error responses happen **sometimes**, these builds may circumvent the problem.

{% hint style="warning" %}
If the error responses happen **frequently or permanently**, KONNEKT will not work properly, since KONNEKT relies on a proper availability of SharePoint Online.
{% endhint %}

## Similar Problems

Please also check this pages:

[Some sites or libraries do not appear in KONNEKT](/troubleshooting/causes-of-missing-content/some-sites-or-libraries-do-not-appear-in-konnekt)

[Libraries are empty](/troubleshooting/causes-of-missing-content/empty-libraries/libraries-are-empty)


# Some sites or libraries do not appear in KONNEKT

## Problem

SharePoint Online sites or libraries which should be mapped via auto mapping do not appear in KONNEKT.

## Background

KONNEKT runs a search on SharePoint Online to discover sites & libraries. To find libraries here, the user must be a member of the site.

In some cases, users may be owners of a site, but not members. This results in not discovered sites or libraries.

## Solution

Ensure, that owners of sites are also members. See [here](https://docs.microsoft.com/en-us/sharepoint/troubleshoot/search/search-results-dont-appear-for-group-owners) for more details.

### Similar Problems

Please also check this page: [Sites missing or folders empty](/troubleshooting/causes-of-missing-content/sites-missing-or-folders-empty)


# Clicking a share does nothing

This is most likely caused by the missing registration of the **KONNEKT** network provider. Please verify of you can open **OneDrive.** If you cannot open the folder add the following registry entry to your system:

```
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
"ProviderOrder"="konnekt,RDPNP,LanmanWorkstation,webclient"
```

You may also want to have a look at this: [All libraries are empty](/troubleshooting/causes-of-missing-content/empty-libraries/libraries-are-empty)


# Debug log preparation

Our support team may ask you to provide debug logs to analyze issues. To do so, please follow these steps:

{% stepper %}
{% step %}

## **Set Log-Level to Debug:**

* Right-Click on the KONNEKT Tray Icon and choose "Preferences"

<figure><img src="/files/HFeat2j3pC5AH6CJHPuV" alt=""><figcaption></figcaption></figure>

* Set Log-Level to "Debug":

<figure><img src="/files/aUsbqUvcmW6WtRTCTrFb" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

## Restart the affected machine

{% endstep %}

{% step %}

## Try to reproduce the Issue

When trying to reproduce the problem, please note the use case you are trying. A description of the steps with details of the path, file name, and timestamp is very helpful when troubleshooting.
{% endstep %}

{% step %}

## Wait a moment and close KONNEKT

Wait up to a minute, then close KONNEKT via the Taskbar Tray icon.

<figure><img src="/files/gHXq0ybqGiBKqxrXQ3k8" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

## Collect the logs

Run crashguard.exe "as administrator" and click "Send report":

"C:\Program Files\Konnekt\crashguard.exe"

<figure><img src="/files/5iTuS2W2R1uo99sPuByh" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
In certain situations, a report cannot be sent due to company restrictions. In such cases, an email window may appear, or the new zipped folder will be saved on your Desktop.
{% endhint %}
{% endstep %}

{% step %}

## Send to us

After submitting the report, please send us a brief email:

* Use case / what went wrong?
* Timestamp / when did it happen?
* Path / file name
  {% endstep %}
  {% endstepper %}


# Failed to open Device

## Problem

#### Issue with ARM-based Systems and KONNEKT Installation

If you notice the tray icon turning red and see log entries like the following, it indicates the issue:

<pre><code><strong>[error][Core_DriverControl] Failed to open Device "\.\konnektDevice"
</strong>[error] [Sharepoint] Failed to create registry key 'Site name': 0815
</code></pre>

The problem occurs on some devices that operate on ARM processors. When KONNEKT's x64 version is installed or deployed on such a system, the installation may succeed. However, KONNEKT will not work as expected.

## Solution

Install KONNEKT's ARM64 version.

{% embed url="<https://trial.konnekt.io/>" %}


# How to change the tenant name

There is one option to change the tenant name.

With KONNEKT version 2.10 the behavior has changed what KONNEKT refers as tenant name. By enabling "[Enhanced OAuth](/configuration/system-settings/enhanced-authentication)" this setting will take affect.

All KONNEKT versions from 2.9.1 and earlier are using the initial tenant name. By enabling the setting "Enhanced OAuth" this behavior will change. Instead it will show the default tenant name that can be set via Microsoft Admin Center.

{% hint style="info" %}
Takes affect with KONNEKT version 2.10 and above
{% endhint %}

Steps that needs to be done by administrators or users are:

* Enabling "Enhanced OAuth" via GPO or Intune policy
* Apply the new App registration in Azure
* delete previous user data from the user registry

{% hint style="warning" %}
The UNC path will change after enabling this setting!

For example, if there are references between files or folders, these links will break!
{% endhint %}


# How to deal with error(s)

On this page, we will explain how to deal with errors that occurred for any reason, without losing your uploaded/edited files.

Sometimes and for different reasons (connectivity problems, throttling..) the upload process could be interrupted and failed, this will give an error for each file and the files will be kept in Cache Folder:

```
%localappdata%\konnekt\cache
```

{% hint style="danger" %}
When error(s) occurs, files will remain in Cache folder until you deal with them.
{% endhint %}

The error(s) will be shown in KONNEKT Explorer window under **Errors**

![](/files/-MfWjMwm-reQrf-t_iCZ)

By right mouse click on an error three options:

* **Retry failed upload:** this will retry the upload process again. If it success the error will automatically disappear
* **Export file to download folder:** this will export the file to your user download folder and delete the error automatically
* **Discard your changes:** this option will ignore the error without saving the file

![](/files/-MfWlF7vCN75Ne6h34uw)

### Deleting all Errors together

{% hint style="info" %}
This feature is applicable to version 2.0 and above
{% endhint %}

In some cases, you want to ignore all errors together (e.g. to free the Cache folder space), you can do it by right click on KONNEKT Icon in Explorer window and **Close file errors**

![](/files/-MfWlrszF1ZVoci8b-Gj)


# Manual uninstallation

{% hint style="info" %}
To uninstall KONNEKT from your system, we recommend to use the uninstaller that is part of KONNNEKT and can be activated via the *add remove software* dialog of Windows.
{% endhint %}

However, if you can not leverage the uninstaller or there are settings left on your system after running the uninstaller, you may use the information given on this site, to remove KONNEKT from your system.

{% hint style="danger" %}
This procedure is for IT pros, only. It is not supported by our service team.
{% endhint %}

## Remove Installer

* Open **Regedit** and go to\
  `HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall`
* Check the GUID-named subkeys for the one that belongs to KONNEKT
  * Check the DisplayName for '**Konnekt'**
  * Check the Publisher for '**glueckkanja-gab AG'**
* Delete the whole key

## Remove Driver

* Run `net stop konnekt`
* Delete `c:\windows\system32\drivers\konnektrx.sys`
* Delete `C:\Windows\System32\konnektnp.dll`

## Remove the shell extensions

* Run `regsvr32 /unregister "C:\Program Files\Konnekt\shellext.dll`
* Remove the following Windows Registry keys for **every user** on the machine:

  ```
  HKCU\SOFTWARE\Classes\Access.Application.16\shell\konnekt
  HKCU\SOFTWARE\Classes\Excel.Sheet.12\shell\konnekt
  HKCU\SOFTWARE\Classes\Excel.Sheet.8\shell\konnekt
  HKCU\SOFTWARE\Classes\Excel.SheetMacroEnabled.12\shell\konnekt
  HKCU\SOFTWARE\Classes\PowerPoint.Show.12\shell\konnekt
  HKCU\SOFTWARE\Classes\PowerPoint.Show.8\shell\konnekt
  HKCU\SOFTWARE\Classes\PowerPoint.ShowMacroEnabled.12\shell\konnekt
  HKCU\SOFTWARE\Classes\Word.Document.12\shell\konnekt
  HKCU\SOFTWARE\Classes\Word.Document.8\shell\konnekt
  HKCU\SOFTWARE\Classes\Word.DocumentMacroEnabled.12\shell\konnekt
  ```

## Clean the registry

Remove the following Windows Registry keys on the **machine**:

```
HKLM\SYSTEM\CurrentControlSet\Services\konnekt
HKLM\SOFTWARE\GlueckKanja\Konnekt
HKLM\SOFTWARE\Policies\GlueckKanja\Konnekt
```

Remove the following Windows Registry keys for **every user** on the machine:

```
HKCU\SOFTWARE\GlueckKanja\Konnekt
HKCU\SOFTWARE\Policies\GlueckKanja\Konnekt
```

## Clean Folders

* Delete the "Konnekt" folder under `%localappdata%`
* Delete `C:\Program Files\Konnekt`

## Restart

Some of the changes (like driver or the shell extensions) may need

* a reboot\
  or
* log-off & log-on\
  or
* restart the explorer with this procedure:
  * Navigate to Task Manager
  * Search for Explorer
  * Right-click on it
  * Click Restart.

If you are unsure, please reboot.


# Office shows outdated versions

## Situation

When using Microsoft Office with KONNEKT on various platforms, the latest version may not appear in applications like Word.

A message may also be displayed: "Recommended update: a newer version of this file is available on the server".

## Problem

Occasionally, Word, Excel, and PowerPoint may show a cached file version instead of the most recent version from SharePoint Online (SPO).

## Solution

There are two methods to resolve these issues:

1. Manually clear the Office cache at `%localappdata%\Microsoft\Office\16.0\OfficeFileCache`.
2. Enable "Delete files from the Office Document Cache when they are closed" in an Office app per user.

<figure><img src="/files/EGqBWeBNPwvHI0Dplsuk" alt="Excel Options \ Save \ Cache Settings"><figcaption></figcaption></figure>


# Opening MS Office documents display a warning message

You might see this error message when KONNEKT **Office Co-Authoring** is enabled.

![](/files/-MA68W386qIGW9EmVRcy)

## **Background**

The issue behind this warning is the restrictions of Microsoft site zones.

## **Solution 1**

To prevent this warning, you need to add the server shown in the error message to the **Trusted Sites** **Zone** in the Internet Explorer setting.

## **Solution 2**

* Open either Word, Excel or PowerPoint on the desktop
* Select **File**
* Select **Options**
* Select **Trust Center**
* Select **Trust Center Settings**
* Select **Trusted Locations**
* Select **Add New Location...**
* Add the shown domain of your practice's OneDrive
* Checkmark "**Sub folders of this location are also trusted**"
* Click **OK** to save.

{% hint style="info" %}
More details can be found under "[Add KONNEKT paths as Trusted sites](/troubleshooting/add-konnekt-paths-as-trusted-sites)".
{% endhint %}


# PDF preview broken after Windows 11 update

## Situation

After installing the October 2025 cumulative update ([KB5066835](https://support.microsoft.com/en-us/topic/october-14-2025-kb5066835-os-builds-26200-6899-and-26100-6899-1db237d8-9f3b-4218-9515-3e0a32729685)), many users noticed that PDF files no longer render in File Explorer’s preview pane. Instead, a warning appears:

> "The file you are attempting to preview could harm your computer. If you trust the file and the source you received it from, open it to view its contents."

This behavior is **intentional** in 25H2. Windows now enforces stricter handling of files tagged with **Mark of the Web (MOTW) -** a security label applied to files downloaded from the internet or network shares. The preview pane refuses to render such files unless they are explicitly trusted.

## Solution

Users can add the UNC path of their KONNEKT to the list of trusted sites:

```
\\OneDrive-<TenantDefaultName>
```

<figure><img src="/files/bNKep9p6WWIgnlJvc9ZW" alt=""><figcaption></figcaption></figure>

**Registry Path**:

```
Computer\HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\onedrive-<TenantDefaultName>
```

Add an entry named "file" as a REG\_DWORD and set its value to 2.

<figure><img src="/files/DB9HCPoNZ1BzOg8vHtz4" alt=""><figcaption></figcaption></figure>

### Recommendation

It is generally recommended to set this entry via an Intune policy or GPO; either per user or per device.

<figure><img src="/files/ZUfIBxNg6PYuM9o5LRhH" alt=""><figcaption></figcaption></figure>


# Risky action blocked

## Situation

Working with Attack Surface Reduction (ASR) rules can cause Windows to block KONNEKT performing some of it's main actions.

{% embed url="<https://learn.microsoft.com/en-us/defender-endpoint/attack-surface-reduction-rules-reference>" %}

## Problem

Without exclusion KONNEKT crashes when trying to open or preview an Office file e.g. Word, Excel or PowerPoint.

In this case check for entries under Windows Security / Protection History:

<figure><img src="/files/lkktjA26vzZzKTH9m3MH" alt=""><figcaption></figcaption></figure>

## Solution

Exclude KONNEKT from the ASR rule "Office Child Process":

"C:\Program Files\Konnekt\Konnekt.exe"

"C:\Program Files\Konnekt\KonnektStarter.exe"

{% embed url="<https://learn.microsoft.com/en-us/defender-endpoint/attack-surface-reduction-rules-reference#block-all-office-applications-from-creating-child-processes>" %}


# Reproduce file issues with Graph Explorer

When users report slow browsing, failed file opens, or other file operation errors and KONNEKT debug logs show Graph API errors, Microsoft Graph Explorer lets you reproduce the failing request directly in the browser. This isolates whether the root cause is on the Microsoft 365 backend or in KONNEKT, and produces clean evidence for a Microsoft support ticket.

{% hint style="info" %}
Microsoft Graph Explorer is a free, browser-based tool from Microsoft. It sends requests to the Microsoft Graph API, which is the same interface KONNEKT, the Microsoft OneDrive sync app, Microsoft Teams, and Microsoft 365 itself use to read and write SharePoint Online and OneDrive files. No installation is required.
{% endhint %}

## When to use this guide

Use this procedure when:

* Multiple users report the same issue at the same time (often a sign of a backend problem).
* KONNEKT debug logs show Graph API errors (HTTP 429, 500, 503, 504, or `UnknownError`).
* You need to prove to Microsoft support that the issue is not caused by third-party software.
* Intermittent slowness persists after the usual KONNEKT checks have been ruled out.

### Collect and inspect the debug log

The normal way to get KONNEKT logs to support is by running `crashguard.exe` from `C:\Program Files\Konnekt`. That flow packages the logs and uploads them silently in the background - in most cases, neither the user nor the admin notices anything happening. See [Debug log preparation](https://docs.konnekt.io/troubleshooting/debug-log-preparation) for the standard support workflow.

The Graph Explorer workflow is different: you need to open the log file yourself, locally, to copy the failing request URL and `request-id` into Graph Explorer. The log files are located at:

```
%LOCALAPPDATA%\Konnekt
```

KONNEKT keeps up to six rotating log files of about 1 MB each. Sort by modification time and start with the most recent file. Open it in a text editor and search for `error` or for the HTTP status code you are investigating (for example, `504`).

Before reproducing the issue, set the log level to **Debug** so that full Graph API request URLs and responses are captured. See [Logging](https://docs.konnekt.io/configuration/system-settings/logging) for how to change the log level via the Preferences UI, the registry, or a managed policy.

### What a Graph API error looks like in the KONNEKT log

A typical error entry:

```
[2026-04-22 14:14:25.281] [22380] [error] [RESTkitClient] Http request (OneDriveClient::GetItemByPath)
GET: https://graph.microsoft.com/v1.0/drives/b!YbLv.../root:%2F...%2F03:?$select=remoteItem,id,name,... - 504
    error: Unrecognized response(504)
    "{"error":{"code":"UnknownError","message":"","innerError":{
      "date":"2026-04-22T12:14:25",
      "request-id":"dc38b1d9-cd9d-4f3d-b75a-5448695fa719",
      "client-request-id":"dc38b1d9-cd9d-4f3d-b75a-5448695fa719"
    }}}"
```

Note these values for later steps:

* The full `GET` URL (copy everything up to, but not including, the HTTP status code).
* The HTTP status code (504 in this example).
* The `request-id` value. Microsoft support can trace the failed request using this ID.

## Prerequisites

* Access to the affected user's Microsoft 365 account, or the user available to sign in themselves.
* A modern web browser (Microsoft Edge, Chrome, Firefox, or Safari).
* The exact file path and file name reported by the user, or the Graph API URL from the debug log.
* Global Administrator access to the Microsoft 365 admin center (only if you plan to open a Microsoft support ticket).

{% hint style="warning" %}
You must sign in as the user who is experiencing the issue, not as an administrator. Using a different account changes the permissions and file access, which invalidates the test.
{% endhint %}

## Step 1: Open Graph Explorer

1. Open your browser and navigate to `https://developer.microsoft.com/graph/graph-explorer`.
2. Click **Sign in** in the top-left corner.
3. Sign in with the credentials of the affected user.

## Step 2: Grant the required permissions

Graph Explorer uses delegated permissions. For file-related tests, grant the following scopes:

| Scope            | Purpose                                                 |
| ---------------- | ------------------------------------------------------- |
| `User.Read`      | Read the signed-in user's profile                       |
| `Files.Read`     | Read the user's OneDrive files                          |
| `Files.Read.All` | Read all files the user has access to                   |
| `Sites.Read.All` | Read items from SharePoint sites the user has access to |

To grant the scopes:

1. In Graph Explorer, click the **Modify permissions** tab below the query input.
2. Locate each scope in the list.
3. Click **Consent** next to each scope.
4. Accept the consent prompt.

For the full scope reference, see [Microsoft's permissions reference](https://learn.microsoft.com/graph/permissions-reference).

## Step 3: Run a test query

Set the HTTP method to `GET` and enter one of the queries below in the request URL field. Replace placeholder values in curly braces with real values.

### Option A: Reuse the URL from the KONNEKT debug log

Copy the full URL from the log line that starts with `GET: https://graph.microsoft.com/...`. Paste everything up to (but not including) the HTTP status code into the Graph Explorer URL field.

This is the preferred option because it reproduces the exact request that failed.

### Option B: Build the query manually

To list the user's OneDrive root folder:

```
GET https://graph.microsoft.com/v1.0/me/drive/root/children
```

To access a specific file by path:

```
GET https://graph.microsoft.com/v1.0/me/drive/root:/Documents/Reports/example.pdf
```

To access a file on a SharePoint site, first get the site ID:

```
GET https://graph.microsoft.com/v1.0/sites/{hostname}:/{site-path}
```

Then query the file using that site ID:

```
GET https://graph.microsoft.com/v1.0/sites/{site-id}/drive/root:/Shared Documents/Folder/example.pdf
```

Click **Run query** and review the response panel.

## Step 4: Interpret the result

The response pane shows an HTTP status code and a JSON body. Use the table below to classify the result and decide the next step.

| Status code                                                                   | Meaning                                                                | Next step                                                                                                                                                    |
| ----------------------------------------------------------------------------- | ---------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `200 OK`                                                                      | The Graph API call succeeded. The file is accessible at the API level. | The issue is on the KONNEKT side or in the client environment. Return to the [Troubleshooting hub](https://docs.konnekt.io/troubleshooting).                 |
| `401 Unauthorized`                                                            | The token is missing, expired, or invalid.                             | Sign out of Graph Explorer and sign in again. If the error persists, see [Access token issues](https://docs.konnekt.io/troubleshooting/access-token-issues). |
| `403 Forbidden`                                                               | The signed-in user does not have permission for this file or site.     | Not a KONNEKT or Microsoft backend issue. Verify permissions in the SharePoint web interface.                                                                |
| `404 Not Found`                                                               | The file or folder does not exist at the given path.                   | Verify the path. The file may have been moved, renamed, or deleted.                                                                                          |
| `429 Too Many Requests`                                                       | SharePoint Online throttling.                                          | Microsoft-side rate limiting. Check the `Retry-After` header, wait, and retry. Throttling prevention settings can reduce recurrence.                         |
| `500 Internal Server Error`, `503 Service Unavailable`, `504 Gateway Timeout` | Microsoft backend error.                                               | The issue is on the Microsoft side. Continue with the next steps.                                                                                            |
| `UnknownError` in the response body                                           | Microsoft backend error without a specific code.                       | Same as above. Capture the `request-id` and open a Microsoft support ticket.                                                                                 |

## Step 5: Capture evidence

Before closing Graph Explorer, document the test. Good evidence makes support tickets faster to resolve.

Collect:

* A screenshot of the Graph Explorer window showing the query URL, the HTTP status code, and the response body.
* The date and time of the test, including time zone.
* The signed-in user's UPN (for example, `user@contoso.com`).
* The exact file path that was tested.
* The `request-id` value from the JSON response body.
* For intermittent errors, repeat the query several times and capture each result.

## Step 6: Open a Microsoft support ticket

Only follow this step if Graph Explorer returned a 500, 503, 504, or `UnknownError` response.

1. Navigate to `https://admin.microsoft.com` and sign in with a Global Administrator account.
2. Go to **Support** -> **New service request**.
3. Select **SharePoint Online** or **OneDrive for Business** as the affected service, matching the endpoint that failed.
4. Describe the issue and attach the screenshots from the previous step.
5. Include the `request-id` from both the KONNEKT debug log and the Graph Explorer response. This allows Microsoft to trace the exact failed requests.
6. State explicitly that the issue was reproduced in Microsoft Graph Explorer.

{% hint style="info" %}
Including Graph Explorer evidence signals that third-party causes have already been ruled out. Microsoft support typically routes these tickets faster.
{% endhint %}

## Common Graph API endpoints

Quick reference for the endpoints most often seen in KONNEKT debug logs:

| Operation                   | Endpoint                                         |
| --------------------------- | ------------------------------------------------ |
| User profile                | `GET /me`                                        |
| OneDrive root listing       | `GET /me/drive/root/children`                    |
| File by path (OneDrive)     | `GET /me/drive/root:/{path}`                     |
| File by item ID             | `GET /drives/{drive-id}/items/{item-id}`         |
| Site by hostname and path   | `GET /sites/{hostname}:/{site-path}`             |
| SharePoint drives on a site | `GET /sites/{site-id}/drives`                    |
| File content download       | `GET /drives/{drive-id}/items/{item-id}/content` |
| Delta query                 | `GET /drives/{drive-id}/root/delta`              |

For the full reference, see the [Microsoft Graph Drive API](https://learn.microsoft.com/graph/api/resources/drive).

### Similar Problems

* [Sites missing or folders empty](https://docs.konnekt.io/troubleshooting/causes-of-missing-content/sites-missing-or-folders-empty) - for SharePoint Search backend errors
* [Access token issues](https://docs.konnekt.io/troubleshooting/access-token-issues) - for 401 Unauthorized responses
* [How to deal with error(s)](https://docs.konnekt.io/troubleshooting/how-to-deal-with-error-s) - for errors on specific files
* [Debug log preparation](https://docs.konnekt.io/troubleshooting/debug-log-preparation) - how to collect logs with Graph API details
* [Logging](https://docs.konnekt.io/configuration/system-settings/logging) - log level configuration


# Slow performance or errors caused by antivirus scanning

## Problem

After deploying KONNEKT, users experience one or more of the following symptoms on mapped drives:

* Browsing folders is noticeably slow or times out
* Opening files takes much longer than expected
* File uploads fail intermittently (errors appear under **Errors** in the KONNEKT Explorer window)
* The KONNEKT tray icon briefly turns red during normal usage

These symptoms are often **intermittent,** they appear during certain times of the day (typically mornings) and resolve on their own after some time.

## Background

KONNEKT works online. Every file read on a KONNEKT mapped drive results in a request to SharePoint Online via the Microsoft Graph API. Microsoft applies **throttling limits** to these requests. When the limit is exceeded, SharePoint Online responds with HTTP 429 (Too Many Requests) and KONNEKT must wait before retrying.

Real-time antivirus (AV) scanning is one of the most common causes of unexpected throttling. When AV software scans a KONNEKT drive letter, it reads every file it encounters. Each file read consumes API capacity (called **Resource Units**). A single AV sweep of a library with 5,000 files can consume significant API capacity in a very short time, leaving little room for actual user activity.

This affects all real-time AV products, including:

* Microsoft Defender for Endpoint
* CrowdStrike Falcon
* SentinelOne
* Sophos
* Other endpoint protection platforms

> **Note:** This is not a bug in KONNEKT or in your AV software. It is expected behavior when real-time scanning is applied to an online-only drive. The solution is to exclude KONNEKT paths from real-time scanning.

## Solution

Add exclusions for KONNEKT drive letters and processes in your AV product. The exact steps depend on your AV solution and management method.

### Microsoft Defender via Intune (recommended)

If **Tamper Protection** is managed via Intune, you must configure exclusions through Intune Endpoint Security policy. PowerShell commands will not work when Tamper Protection is enabled.

1. Open the **Microsoft Intune admin center**
2. Navigate to **Endpoint security** > **Antivirus**
3. Create or edit a **Microsoft Defender Antivirus** policy
4. Under **Configuration settings**, add the following:

**Path exclusions:** add each KONNEKT drive letter your organization uses, e.g.:

```
M:\
S:\
K:\
```

**Process exclusions:**

```
C:\Program Files\Konnekt\Konnekt.exe
C:\Program Files\Konnekt\KonnektStarter.exe
```

5. Assign the policy to the appropriate device or user groups
6. Allow time for the policy to sync to endpoints

### Microsoft Defender via PowerShell (fallback)

If Tamper Protection is **not** managed via Intune, you can use PowerShell:

```powershell
Add-MpPreference -ExclusionPath "M:\"
Add-MpPreference -ExclusionPath "S:\"
Add-MpPreference -ExclusionProcess "C:\Program Files\Konnekt\Konnekt.exe"
Add-MpPreference -ExclusionProcess "C:\Program Files\Konnekt\KonnektStarter.exe"
```

> **Important:** Replace `M:\` and `S:\` with the actual drive letters used in your KONNEKT deployment. If you use auto-mapping, consider which drive letters are assigned to your users.

### Microsoft Defender - Attack Surface Reduction (ASR) rules

If you use ASR rules, also see "[Risky action blocked](/troubleshooting/risky-action-blocked)" for additional KONNEKT exclusions required for ASR.

### CrowdStrike Falcon

1. Open the **Falcon console**
2. Navigate to **Endpoint security** > **Prevention policies**
3. Under **Machine Learning** and / or **Sensor Visibility Exclusions**, add:

**Directory exclusions:** Your KONNEKT drive letters (e.g. `M:\`, `S:\`)

**Process exclusions:** `Konnekt.exe`, `KonnektStarter.exe`

### SentinelOne

1. Open the **SentinelOne Management Console**
2. Navigate to **Sentinels** > **Exclusions**
3. Add **Path Exclusions** for your KONNEKT drive letters
4. Add **Process Path** exclusions for:

```
C:\Program Files\Konnekt\Konnekt.exe
C:\Program Files\Konnekt\KonnektStarter.exe
```

### Other AV products

For any other AV product, configure the following exclusions in your endpoint protection management console:

| Exclusion type   | Value                                         |
| ---------------- | --------------------------------------------- |
| Path / Directory | Each KONNEKT drive letter, e.g. `M:\`, `S:\`  |
| Process          | `C:\Program Files\Konnekt\Konnekt.exe`        |
| Process          | `C:\Program Files\Konnekt\KonnektStarter.exe` |

## How to verify the issue

If you are unsure whether AV scanning is causing the problem, you can check using the following steps:

1. Open the KONNEKT **Preferences** (right-click the KONNEKT tray icon)
2. Set **Log-Level** to **Debug** (see also Debug log preparation)
3. Reproduce the slow behavior
4. In the debug log, look for repeated entries indicating throttling (HTTP 429 responses or retry messages) during periods when no user is actively working with files

If you see throttling entries occurring at regular intervals or during times when AV scheduled scans are configured, this strongly indicates AV scanning as the cause.

## Recommendation

We recommend configuring AV exclusions for KONNEKT drive letters and processes **before** deploying KONNEKT to end users. This prevents throttling incidents from occurring during rollout and avoids user-facing errors that may generate unnecessary support tickets.

It is generally recommended to deploy these exclusions via **Intune policy** or **GPO** to ensure they are applied consistently across all devices.

See also: [Offline attribute](/configuration/system-settings/offline-attribute), KONNEKT's built-in mechanism to reduce bandwidth usage from previews and indexing.


# Subscribe a subset of users

It is allowed to subscribe KONNEKT for a subset of the SharePoint Online users in a tenant. Please see our [licensing guide](/licensing) for details on licensing.

However, there are some things, you should care about, to ensure proper usage:

* Assign license key to subscribed users, only
* Install KONNEKT on machines with subscribed users, only

## Assign licenses

You must make sure, that only those users, who are subscribed to KONNEKT have a license key. To achieve this, please assign the license key on a user-basis, only:

* Disabled the license key on the machine level on all machines.
* Set the license key on user level for all users that are subscribed to KONNEKT.

Details on how to set license keys can be found [here](/configuration/other/license-key-on-multi-user-environments).

## Disable KONNEKT on machines

You should install KONNEKT on machines with subscribed users, only.

In case of multi-user systems like VDI, there may be machines, where both types of users (subscribed/non-subscribed) are working. In those cases, you should prevent, that KONNEKT is generating an account for non-subscribed users. You can do this by disabling the Account Setup Wizard for the non-subscribed users. You can find details on this [here](/configuration/system-settings/configure-konnekt-for-a-subset-of-users).

{% hint style="warning" %}
Once you have installed KONNEKT on a machine, you must disable the Account Setup Wizard prior the first login of the user(s) to be effective.
{% endhint %}


# What is the maximum path and file name length?

KONNEKT has to respect the path and file name length limits of both worlds:

* **SharePoint Online**\
  and
* **Windows**.

The maximum length of a filename including path is **260 characters** in total.

It consists of path and file name:

* **path** is: `\\onedrive-<yourTenant>\<site>\<library>\<foldernames>\`\
  It is limited to 248 characters.
* **file name** is: `<name>.<extension>`\
  12 characters are always preserved for the file name (8.3). Path and file name together must not exceed the limit of 260 characters in total.

These limits are mainly caused by Windows OS and File Explorer restrictions. Details can be found [here](https://docs.microsoft.com/en-us/windows/win32/fileio/maximum-file-path-limitation?tabs=cmd).


# Why is there a grey "X" or "brown suitcase" on my files and folders?

KONNEKT users (Windows 10 or earlier) may see a grey "X" on file and folder icons in Windows File Explorer.

![](/files/-McTOP8dst7YDgHR148w)

In Windows 11 it looks like

<figure><img src="/files/V5fsR3bGjyf9qtzDJAqk" alt=""><figcaption></figcaption></figure>

**This is not an Error or a Problem.** You can still work with your files without any restrictions.

This is a visualization in Windows Files Explorer of a setting that KONNEKT folders and files have, to save bandwidth.

**Background:**

The setting is called "FILE\_ATTRIBUTE\_OFFLINE". It indicates to the operating system, that this file or folder is not available immediately. As a result, Windows File Explorer does not generate previews for the files.

**Workaround:**

This symbol comes usually after a new installation, as a workaround, you can restart the Windows file explorer to remove it.

**We use this setting with KONNEKT files & folders to save bandwidth between the client and SharePoint Online.**

The visualization is not visible to every client.

See also: [Offline attribute](/configuration/system-settings/offline-attribute)


# Changelog

{% hint style="success" %}
If you'd like to **stay up to date on the latest changes and news in the KONNEKT changelog**, you can subscribe to our email update service. Subscribers will receive **email notifications** when there are new updates to the changelog.

[**Please click here to sign up for email notifications**](https://feedback.konnekt.io/)**.**
{% endhint %}

## Versions

### 2.12.1 (Published 2026-07-15)

Fix:

* SharePoint throttling: Reduced likelihood of hitting rate limits
* Login fails for UPNs from domains with multi-label public suffixes
* File downloads could fail on SharePoint Online due to an invalid tempauth token
* Proxy detection could fail on Windows
* Stability improvements

**Downloads**

* [KONNEKT 2.12.1.0 Windows X64 64 Bit](https://trial.konnekt.io/releases/Konnekt-X64-2.12.1.0.Msi)
* [KONNEKT 2.12.1.0 Windows X86 32 Bit](https://trial.konnekt.io/releases/Konnekt-X86-2.12.1.0.Msi)
* [KONNEKT 2.12.1.0 Windows ARM 64 Bit](https://trial.konnekt.io/releases/Konnekt-Arm64-2.12.1.0.Msi)
* [KONNEKT ADMX-ADML 2.12.0.0](/configuration/management-options#admx-adml-files)

### 2.12.0 (Published 2026-04-08)

Add:

* Policy [Office365 Co-Authoring](/configuration/system-settings/office365-co-authoring) extended to open office files in Browser with Office Online

Fix:

* SharePoint site discovery might fail if user UPN contains custom DNS subdomain
* [Managed mappings](/configuration/mappings/managed-mappings) drive deleted after some time
* Stability improvements

### 2.11.4 (Published 2025-12-01)

Fix:

* Stability improvements

### 2.11.3 (Published 2025-09-18)

Add:

* Ratelimit header evaluation for dynamic throttling prevention

Fix:

* Stability improvements

### 2.11.2 (Published 2025-08-04)

Fix:

* [Managed mappings may result in empty drive](/troubleshooting/causes-of-missing-content/empty-libraries/empty-document-libraries-for-managed-mappings)
* Stability improvements

### 2.11.1 (Published 2025-06-23)

Fix:

* Stability improvements

### 2.11 (Published 2025-05-19)

Add:

* Enhanced [SharePoint throttling prevention](/configuration/system-settings/throttling-prevention) by introducing [local limits based on the number of requests per time (client side throttling)](/configuration/system-settings/throttling-prevention/throttling-prevention-client-side)
* Support for Sensitivity Labels with Microsoft Purview Information Protection (fka Microsoft Information Protection MIP) in non-co-authoring scenarios (e.g. PDF files)
* Improved handling in co-authoring scenarios, when multiple files are opened simultaneously with Windows File Explorer

Fix:

* Renaming files mapped on a drive letter may result in an error: "Can't read from the source file"
* Directories may disappear when client has network issues
* Account creation may fail if user name contains multibyte characters (e.g. kanji)
* Optimized behavior for sites, libraries and files with read-only permissions
* Stability improvements

### 2.10.2 (Published 2024-12-12)

Add:

* Silent authentication for SSO-enabled environments (80)

Fix:

* Improved proxy detection (9669)
* Moving and renaming files sometimes not stable (9594)
* Stability improvements

### 2.10.1 (Published 2024-11-22)

Fix:

* Improved SharePoint throttling management
* Parsing errors when checking `IsSiteReadOnly` on some SharePoint sites
* Opening Microsoft Office templates files from some drives opens the template instead of creating new document from template
* Shellext.dll might cause crashes
* Stability improvements

### 2.10 (Published 2024-08-28)

Add:

* Opt-in to [new OAuth component](/configuration/system-settings/enhanced-authentication) (EnhancedOAuth)
  * New Azure app registration
  * New permissions set with fewer permissions required
  * Uses OAuth 2.0 API routes
  * Namespaces are built from [default domain](https://learn.microsoft.com/en-us/microsoft-365/admin/setup/domains-faq?view=o365-worldwide#how-do-i-set-or-change-the-default-domain-in-microsoft-365) (\\\onedrive-\<DefaultDomainName>\\...), no longer from [initial domain](https://learn.microsoft.com/en-us/microsoft-365/admin/setup/domains-faq?view=o365-worldwide#how-do-i-set-or-change-the-default-domain-in-microsoft-365) (\\\onedrive-\<InitialDomainName>\\...).
  * Intune DeviceIDs are sent during authentication
  * Works with Conditional Access policies, when using excluded apps (743)
* Improved lock and read-only check for files and directories (725)
* Added Co-Authoring for editing (="open") Microsoft Office templates in Windows File Explorer context menu. (68)

Fix:

* File Explorer cannot handle sites ending with a blank character (63)
* Adobe Acrobat might crash if not run in compatibility mode (67)
* New Notepad cannot save files (invalid function) (8599)
* Stability improvements

### 2.9.1 (Published 2024-02-15)

Add:

* Support for more than 10 KONNEKT Accounts

Fix:

* Account deletion may leave ghost volumes
* Explorer freezes if KONNEKT account or share is removed
* KONNEKT cannot find sites with dot in name when adding shares or managed mappings
* Windows Terminal Servers (Windows Server 2019) may freeze due to konnektrx.sys timeout after Windows Update
* Stability improvements

### 2.9.0 (Published 2023-11-16)

Add:

* Policy to disable Edge Browser component (WebView2)
* Full support of x64 Processes on ARM64 machines

Fix:

* SharePoint throttling: Parsing issues in Retry-After header
* Possible loss of delayed write data if disk IO pressure is high
* ARM64 setup may show a warning
* Gray login window due to failed browser component negotiation
* Stability improvements

### 2.8.0 (Published 2023-10-11)

Add:

* New document from office template in CoAuthoring mode (#30)

Fix:

* Security fix for [libcurl CVE-2023-38545 (HIGH) SOCKS5 heap buffer overflow](https://curl.se/docs/CVE-2023-38545.html)
* Security fix for [libcurl CVE-2023-38546 (LOW)](https://curl.se/docs/CVE-2023-38546.html)
* Malware alarm on konnektUpdate.exe due to missing digital signature (#31)
* Re-authentication not triggered after password reset (#23)
* Uninstall and install with suppressed reboot may lead to uninstalled driver after next reboot (#3855)
* SharePoint mapping might be shown empty when cache TTL is very long (#6)
* Stability improvements

### 2.7.2 (Published 2023-09-07)

Fix:

* Authentication window may be shown without content
* Stability improvements

### 2.7.0 (Published 2023-08-10)

Add:

* "View Online" for a folder directs to corresponding subfolder in SharePoint (591)
* [Managed Mapping supports root site URLs and Teams URLs](/configuration/mappings/managed-mappings#policy-definition) (741)
* Login prompt negotiates for Edge Browser (791)
* File support for OneNote notebooks (2730)
* CoAuthoring for OneNote documents (2730)

Fix:

* "View SharePoint Site" context-menu broken for OneDrive (1509)
* Added favorites lost after log off (2894)
* Stability improvements

### 2.6.0 (Published 2023-07-13)

Add:

* [Circumvent error/outage of SharePoint Search](/troubleshooting/causes-of-missing-content/sites-missing-or-folders-empty) (703)
* [Extend Cache TTL range in policy](/configuration/system-settings/cache-setting#cache-ttl-time-to-live) (756)
* [Policy to configure downloads directory](/configuration/system-settings/download-directory) (792)
* CoAuthoring support for additional file types including .xslb and office template files
* [Ready for new Intune ADMX and ADML administrative templates import (public preview)](/configuration/management-options/setting-for-intune-managed-devices) (753)
  * [New configuration & behavior for "Connect drive" policy](https://docs.konnekt.io/pages/-Mb235Taehto9WssHbcF#konnekt-2.6.0-and-newer) (753)
* New Policies (754)
  * [Skip Account Wizard](/configuration/system-settings/configure-konnekt-for-a-subset-of-users)
  * [Open File Size Limitations](/configuration/system-settings/open-file-size-limitations)

Fix:

* Error when opening certain office files (e.g. XLSB) with sensitivity/encryption enabled (768)
* Kernel driver misinterprets modern standby as deadlocked userland (809)
* Files and Folders named with a single character cause problems in searches (866)
* Stability issues

### 2.5.8 (Published 2023-06-28)

Fix:

* Copy Link To Clipboard fails on SharePoint libraries (1271)
* Konnekt read operations may fail if content-range directive is ignored by SharePoint.
* Error logged when accessing root of document library
* File lock/checkout checks produce parsing erros in log
* Stability issues

### 2.5.7 (Published 2023-05-30)

Fix: App may crash if the access token cannot be obtained

### 2.5.6 (Published 2023-05-25)

Fix: App may crash during SSO login attempt (1046)

### 2.5.4 (Published 2023-05-16)

Fix:

* Poor response times when trying to negotiate HTTP/2 multiplexing (836)
* Managed Mappings showing empty drives when the policy "Add all SharePoint libraries" is disabled (932)

### 2.5.2 (Published 2023-05-11)

Fix:

* Volume free and total size is wrong (896)
* Stability issues

### 2.5.1 (Published 2023-05-10)

Fix: An invalid account token may cause issues (895)

### 2.5.0 (Published 2023-05-08)

* Add
  * Updated API handling
  * Support for [SharePoint Domain Name Change](https://learn.microsoft.com/en-us/sharepoint/change-your-sharepoint-domain-name) (765)
  * Support for Custom/Vanity SharePoint Domain Names (780)
  * [Multi-Geo support ](/configuration/mappings/multi-geo)is always active - no dedicated config needed anymore.
* Fix
  * Unable to install MSI file located in Konnekt share (748)
  * Cannot access sites with names ending on a dot (761)
  * Failed to open .XLSB files when sensitivity/encryption is enabled (768)
  * Move Folder within a library is reversed after some seconds (775)

{% hint style="info" %}
KONNEKT version numbers 2.3 and 2.4 were skipped due to major code rework.
{% endhint %}

### 2.2.1 (2022-12-30 - Bugfix release for KONNEKT 2.2.0)

* Fix
  * Explorer may get unresponsive when creating new folder in SharePoint root - part 2 (648)
  * Deleted folders may re-appear in some scenarios (738)
  * Managed Mapping sometimes not working after machine reboot (763)
  * License check issue in version 2.2.0 (766)

#### Downloads

{% file src="/files/L9opohyagT03czMrD931" %}
KONNEKT 2.2.1.0 (64-Bit, 32-Bit, Arm64 versions are available)
{% endfile %}

### 2.2.0 (Published 2022-11-17)

* ADD
  * [ARM64 processor platform support ](/installation/system-requirements#processor-platform)(662)
  * [SharePoint Throttling Prevention policy](/configuration/system-settings/throttling-prevention/sharepoint-throttling-prevention) (730)
  * [Add to favorites in Managed Mappings](/configuration/mappings/managed-mappings#make-mapping-a-konnekt-favorite) (733)
  * Changed search strategy for folder browsing to work around performance degradation of the Microsoft SharePoint Online REST API (736)
* FIX
  * Explorer may get unresponsive when creating new folder in SharePoint root - part 1 (648)
  * "This file does not exist" after re-install or uninstall (649)
  * Save new file not working in special conditions, e.g. substring of existing file (651)
  * Prevent blue screen during driver update in some environments (672)
  * History misses one backslash in UNC for some entries (721)
  * Deleted folders may re-appear in some scenarios (738)

### 2.1.1 (Published 2022-07-05)

* FIX: Machine policy may not be applied correctly

### 2.1.0 (Published 2022-05-12)

* ADD
  * Multi-Geo support for OneDrive and SharePoint Online
  * Improvements for heavy load environments
  * Remove the limit of 192 libraries per site
  * Logging level policy
* FIX
  * Pinned links in taskbar lead to SPO site instead of UNC
  * CoAuthoring setting in [ADMX](/configuration/management-options/settings-via-gpo#admx-file) not working
  * Installer coordinator issue during setup on some RDS environments
  * Unwanted policy changes after hibernation in some environments
  * "Enable Sharepoint Sites" option not grayed out after applying GPO/Intune policy.
  * Handling of error responses from SharePoint Online causing empty folders
  * "Add site favorite" feature

### 2.0.0 (Published 2021-12-03)

* ADD
  * Customize explorer UI ([Hide several options](/configuration/gui-behavior/konnekt-explorer-ui), [hide tray icon](/configuration/gui-behavior/hide-tray-icon))
  * Custom site scope ([individual search string](/configuration/mappings/auto-mapping))
  * Automatic mappings ([Managed mappings](/configuration/mappings/managed-mappings))
  * [Cache settings](/configuration/system-settings/cache-setting) (individual write handling to SharePoint Online e.g. for VDI environments)
  * [Intune Management](/configuration/management-options/setting-for-intune-managed-devices-1)
  * Offline Attribute Filter to enable explorer previews on certain file types
  * [ADMX & ADML files ](/configuration/management-options/settings-via-gpo#admx-file)got new policies & structure
* FIX
  * Broken file links when resolving mapped drives (e.g. copy path in Outlook)
  * Stability issue when uploading files larger than 1 GB
  * Cache directory may be filled up
  * SharePoint document libraries may be shown empty

### 1.20.0 (Published 2021-04-21)

* ADD: Advanced SharePoint throttle handling
* FIX: Handling of multiple accounts in the same tenant
* FIX: Stability issues under write pressure

### 1.19.0 (Published 2021-04-06)

* ADD: Improve dialog to add shares
* FIX: Konnekt cannot reach driver after upgrade
* FIX: Konnekt needs to be restarted after hibernate

### 1.18.0 (Published 2021-02-10)

* ADD: Improve SSO flow
* FIX: SharePoint token may expire
* FIX: Proxy settings are not reevaluated on network connection changes
* FIX: Path issues if profile path contains umlauts

### 1.16.0 (Published 2020-10-22)

* FIX: Cannot access foreign tenant on Azure AD joined clients
* ADD: Reduce reauthentication frequency

### 1.15.1 (Published 2020-09-24)

* FIX: Explorer unresponsive during move/copy operations
* FIX: Cannot add or remove favorites

### 1.15.0 (Published 2020-09-03)

* FIX: Cannot save as PDF from Google Chrome

### 1.14.1 (Published 2020-07-25)

* FIX: Manually added shares always open default document library

### 1.14.0 (Published 2019-05-14)

* FIX: Cannot save PDF files in several Adobe products
* ADD: Manually add private channels from Teams

### 1.12.6 (Published 2019-04-20)

* FIX: Login issues

### 1.12.4 (Published 2019-02-26)

* FIX: Wild card matching

### 1.12.3 (Published 2019-12-19)

* FIX: Cannot create account (key not found)
* FIX: SharePoint link scope policy
* FIX: License policy order

### 1.12.0 (Published 2019-11-18)

* ADD: Improved handling of additional SharePoint document libraries
* ADD: Configure drive letter for personal OneDrive volume
* ADD: Configure SharePoint link scope (default, organization, anonymous, disabled)
* FIX: Wrong SharePoint sub-group grouping

### 1.10.1 (Published 2019-09-02)

* ADD: Better visualization of upload errors
* FIX: Shell extension does not display any shares if an upload error occurs

### 1.10.0 (Published 2019-08-30)

* ADD: Add account endpoint to sharename if displayed one left side of explorer
* FIX: Double menu in Windows Explorer
* FIX: Account context menu is not completely visible in German language
* FIX: Crash in kernel driver

### 1.9.0 (Published 2019-04-17)

* ADD: Office co-authoring support for old office file formats
* ADD: Add additional SharePoint document libraries as shares
* ADD: Option to remove manually added shares
* ADD: Policy to rename "Konnekt" in the Windows Explorer
* ADD: Rename "Personal" in OneDrive to "OneDrive"
* ADD: Registry setting to set personal folder name in OneDrive

### 1.8.2 (Published 2019-04-02)

* ADD: German localization
* ADD: Display message during volume update
* FIX: Cannot open PDF files in Adobe Acrobat and Acrobat Reader

### 1.8.0 (Published 2019-02-20)

* ADD: Policy for disabling FILE\_ATTRIBUTE\_OFFLINE
* FIX: Improved performance during start-up on terminal servers
* FIX: Office Co-authoring opens wrong URL in personal OneDrive if user was re-created (#366)
* FIX: Co-authoring does not work on mapped network drives
* FIX: Co-authoring does not work for macro enabled Excel files (#360)
* FIX: Remove add account entries for German cloud (#342)
* FIX: Race condition during start-up
* FIX: Driver does not work on Windows 7 x64
* FIX: Improved logging

### 1.7.4 (Published 2018-11-23)

* FIX: Slow performance on terminal service while browsing available site in the shell extension (#304)
* FIX: Co-Authoring not working when using Excel macro enabled files (#360)

### 1.7.1 (Published 2018-10-18)

* FIX: TMP-file creation by MS Office applications (#336)
* FIX: Cannot open PDF files from UNC paths (#340)

### 1.7.0 (Published 2018-09-27)

* ADD: Improved proxy authentication support
* FIX: TMP-file creation by MS Office applications (#336)
* FIX: Improved wild card match of file names
* FIX: Cannot delete account if it is in error state
* FIX: Cannot open PDF files from UNC paths (#340)
* FIX: Enable SharePoint sites is greyed out in settings (#347)
* FIX: Crash in kernel driver

### 1.6.0 (Published 2018-06-15)

* FIX: Personal OneDrive is not updated if it was changed outside of Konnekt
* FIX: Improved rename operations
* FIX: Fixed a race condition during delete

### 1.5.0 (Published 2018-06-05)

* ADD: Support SharePoint sites without any default document library
* ADD: Improve OneDrive provider
* ADD: Set default log level to INFO
* FIX: Race condition during rename operation
* FIX: Crash during startup

### 1.4.15 (Published 2018-05-14)

* ADD: Evaluation version enables SharePoint sites by default
* FIX: Setup fails on Windows Server 2008

### 1.4.10 (Published 2018-05-02)

* FIX: Konnekt creates 0-byte files
* FIX: Potential deadlock in OneDrive provider
* FIX: Update window is not DPI aware

### 1.4.4 (Published 2018-04-09)

* FIX: Update window is not closed after clicking the version number
* FIX: Cannot open multiple PDF files in Acrobat Reader

### 1.4.2 (Published 2018-03-05)

* FIX: Context menu for localized SharePoint sites

### 1.4.1 (Published 2018-02-16)

* FIX: Office co-authoring fails to open url if the UPN contains minus characters

### 1.4.0 (Published 2018-01-30)

* ADD: Faster startup on terminal servers
* ADD: Improve SharePoint volume handling
* ADD: Group policy setting for co-authoring

### 1.3.3 (Published 2017-12-19)

* FIX: Race condition (#303)

### 1.3.2 (Published 2017-12-08)

* FIX: Acrobat Reader not working on Konnekt-UNC path (#216)
* FIX: Cannot save outlook attachments in Konnekt-UNC path on Windows 10 anniversary update (#301, #302)

### 1.3.0 (Published 2017-11-06)

* ADD: Display private SharePoint groups

### 1.2.4 (Published 2017-09-13)

* FIX: Crash during automatic update

### 1.2.0 (Published 2017-09-08)

* FIX: Crash after adding an account
* FIX: Rename open file

### 1.1.0 (Published 2017-08-25)

* ADD: Settings dialog
* ADD: Show favorite and personal shares in explorer's left side
* ADD: Remove chromium embedded framework in favor of MSHTML
* ADD: Automatically create account on first start if computer is joined to an Azure AD
* ADD: Setting to connect first personal volume to drive H:
* FIX: Cannot access SharePoint site if its name contains special characters (#258)
* FIX: Cannot open OneNote file in Konnekt (#261)
* FIX: No content is shown after folder rename (#255)
* FIX: Cannot add O365 account when proxy is used

### 1.0.2 (Published 2017-05-17)

* ADD: License key management
* ADD: Crash dump collects more information

### 1.0.1 (Published 2017-05-15)

* FIX: Cannot save document from website to SharePoint site using MS Edge

### 1.0.0 (Published 2017-05-12)

* FIX: Cannot delete directory if it contains files


# Licensing

{% hint style="success" %}
The subscription for KONNEKT is **user-based**.
{% endhint %}

## User definition

The licensing is per seat, which means that the subscription of a "user" is required for each user (UPN), who is using KONNEKT to log into OneDrive for Business or SharePoint online.

{% hint style="info" %}
In many cases the required amount of KONNEKT subscriptions equals the amount of Microsoft Office 365 / OneDrive for Business / SharePoint Online subscriptions.
{% endhint %}

The minimum amount of users that can be subscribed for one organization is 25.

A user subscription is bound to a single user for at least one calendar month and cannot be shared with other users.

## Device limits per user

A single user may have up to 5 Windows devices or VDI sessions (e.g. Citrix Virtual Apps).

## Subscription scope

The subscription of KONNEKT may be used for the users of one organization. Users from this one organization may access multiple Microsoft 365 tenants with KONNEKT.

It is **not** allowed to

* use one KONNEKT subscription for users from multiple organizations,
* split one KONNEKT subscription and/or re-sell it to multiple organizations.


# Microsoft Marketplace

## Prerequisites <a href="#prerequisites" id="prerequisites"></a>

In order to purchase solutions from independent software vendors (ISV) such as KONNEKT, you must fulfil the following requirements:

1. You have an active Azure subscription in one of the following countries: Armenia, Australia, Austria, Bulgaria, Belgium, Canada, Chile, Colombia, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, India, Indonesia, Ireland, Italy, Kenya, Latvia, Liechtenstein, Lithuania, Luxembourg, Malaysia, Malta, Monaco, Netherlands, New Zealand, Nigeria, Norway, Poland, Portugal, Puerto Rico, Romania, Saudi Arabia, Serbia, Singapore, Slovakia, Slovenia, South Africa, South Korea, Spain, Sweden, Switzerland, Taiwan, Thailand, Türkiye, United Arab Emirates, United Kingdom, United States, Vietnam.
2. The account you want to purchase our solution with must have the **Owner** or **Contributor** role assigned on the Azure subscription you are going to pay with.
3. The billing account linked to your Azure subscription is properly set up. Depending on your billing account type (Microsoft Customer Agreement or Enterprise Agreement), you might need to enable marketplace purchases in the Azure portal first.

## How to purchase KONNEKT?

To get started with your KONNEKT subscription, follow below steps:

{% stepper %}
{% step %}

### Locate [KONNEKT](https://portal.azure.com/#view/Microsoft_Azure_Marketplace/GalleryItemDetailsBladeNopdl/id/glueckkanja-gabag.konnekt-transactable-prod) on the Microsoft Marketplace

* In case we have extended a **Private Offer** to you or your MSP/distribution has extended a **Multiparty Offer (MPO)** to you, navigate to **Marketplace** in your **Azure Portal** and then to **Private Offer Management** to locate the Private Offer.
  * More details on Private Offers and MPOs can be found in Microsoft's documentation.
    * [Private Offer](https://learn.microsoft.com/en-us/marketplace/private-offers-purchase)
    * [Multiparty Offer](https://www.youtube.com/watch?v=TANUlgLuVqI)
* Click **Subscribe**.

<figure><img src="/files/FRkBTfuT7evtsKVKUivu" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

### Subscribe to KONNEKT

* Create or select the **Resource group** you would like to deploy the subscription to.
* Assign a descriptive **Name** to later identify your subscription.
* We recommend to keep **Recurring billing** **On** so that you do not have to worry about an automatic termination of your subscription.
* Click **Review + subscribe** and then **Subscribe** to deploy the **SaaS** resource to your **Resource group**.

<figure><img src="/files/R29Uhi677NXSrC3XG6Db" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
The random order of **Base Fees** und **Additional Users** under the **Price** information is attributed to limitations of the Microsoft Marketplace. Later during the the enrolment process, we will provide you with transparent information on the expected licensing costs.
{% endhint %}
{% endstep %}

{% step %}

### Configure your account

* Once the deployment is complete, please navigate to our platform by clicking **Configure account now**.

<figure><img src="/files/jW1g3lg8N4n84c5S5eCy" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

### Add additional information

After authenticating on our platform using your Microsoft credentials, you will be prompted for additional information, such as the desired total **User** amount and a T**echnical contact**.

{% hint style="info" %}
The **Technical contact** must have a mailbox connected to it, so we are able to notify you in case there are relevant issues with KONNEKT.
{% endhint %}

<figure><img src="/files/vHarDTggdcI97xSYnVMc" alt=""><figcaption></figcaption></figure>

Based on the amount of users provided, we will charge the relevant base fee for your user segment as well as additional users, in case you require more than the included amount in your base fee. **The platform automatically selects the best price / tier**.

The platform will show you the licensing fees you have to expect under **Cost Projection**.

If you are happy with it, please click **Review & Submit** for a final review and a fee summary.

Complete the checkout by confirming your choice and clicking **Submit**.

If you are happy with it, please complete the enrolment by clicking S**ubmit**, which triggers us to generate a license key for KONNEKT. You will receive this key as part of our welcome email including all relevant information on the next steps (e.g. how to install KONNEKT on your clients). This won't take any longer than one business day.

{% hint style="info" %}
You will only be charged by Microsoft, once you have completed the enrolment on our landing page and received our welcome email.
{% endhint %}
{% endstep %}
{% endstepper %}

## Pricing Model

* KONNEKT is offered as an **annual subscription plan** with different [User Segments](#user-segments). The correct **user segment** is automatically selected by our platform based on the amount of desired users.
* The annual subscription plan consists of a **base fee** which includes a certain amount of users per year - depending on the **user segment**. For example, the **base fee** for the user segment *KONNEKT 25* includes 25 users per year.
* If more than the included amount of users is required, **additional users** can be added to the plan. For each additional user, we charge an additional annual per-user fee.

## Invoicing

* During the first subscription interval, your subscription fees are not immediately due after completing the subscription enrolment. Instead we will start billing once your cancellation grace period has expired.
* Upon every renewal date, you will be billed immediately.
* You will always be billed for the entire subscription cycle in advance.
* The related items should appear on your Microsoft Azure invoice (Pay-As-You-Go) the month after we have reported your fees to Microsoft.
* In the PDF invoice you will receive from Microsoft, all KONNEKT fees are lumped into an item called "SaaS". The related Publisher is "glueckkanja".<br>

  <figure><img src="/files/CVS5DmEno08QfLjHNFQV" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
For a more detailed cost breakdown of your base and additional user fees, please refer to the invoice in your Azure portal.
{% endhint %}

## Plan Overview

Subscriptions for KONNEKT are available based on an annual renewal interval.

| **Plan** | **Renewal Interval** |
| -------- | -------------------- |
| KONNEKT  | Annually             |

### User Segments

The following user segments are available.

<table data-header-hidden><thead><tr><th width="240.02162801098973">Plan</th><th width="244.07580174927114">Included Users</th><th></th></tr></thead><tbody><tr><td><strong>User Segment</strong></td><td><strong>Included Users in Base Fee</strong></td><td><strong>Maximum Total Users</strong></td></tr><tr><td>KONNEKT 25</td><td>25</td><td>249</td></tr><tr><td>KONNEKT 250</td><td>250</td><td>999</td></tr><tr><td>KONNEKT 1000</td><td>1,000</td><td>4,999</td></tr><tr><td>KONNEKT 5000</td><td>5,000</td><td>9,999</td></tr><tr><td>KONNEKT 10000</td><td>10,000</td><td>unlimited</td></tr></tbody></table>

For prices in Euro (EUR), please check out our [website](https://www.konnekt.io/pricing/). For prices in *your* currency, please directly refer to the **Marketplace** in the [Azure Portal](https://portal.azure.com/).

## Subscription Management

### User Upgrades

* If you would like to upgrade your user count, you can do that any time during the current subscription cycle by navigating to your **KONNEKT subscription** in the [Azure SaaS portal](https://portal.azure.com/#blade/HubsExtension/BrowseResourceBlade/resourceType/Microsoft.SaaS%2Fresources) and by clicking "Open SaaS Account on publisher's site" (see screenshot below). This will re-direct you to our platform where the amount of users can be upgraded.

![](/files/JxOKqz7oJw7HyD6h4iV7)

* Our platform will inform you about the new fees you to expect for a **complete** subscription cycle.
* For the current cycle, we will bill the additional users for remaining days only.
* After confirming your choice and once we have updated the license in our backend, you will receive a confirmation email from us.

### User Downgrades

* You can **pre-register a reduction** of your licensed users for the **next renewal**, by navigating to your **KONNEKT subscription** in the [Azure SaaS portal](https://portal.azure.com/#blade/HubsExtension/BrowseResourceBlade/resourceType/Microsoft.SaaS%2Fresources) and by clicking "Open SaaS Account on publisher's site" (see screenshot below). This will re-direct you to our platform where the amount of users can be downgraded.

![](/files/JxOKqz7oJw7HyD6h4iV7)

* The downgrade will become effective upon the next regular renewal of your subscription.
* In case you change your mind and would like to change the user quantity or cancel the downgrade altogether, navigate back to your **KONNEKT subscription** and click **Cancel downgrade**.

<figure><img src="/files/kAyQlMvd7e3yH2M2rnxx" alt=""><figcaption></figcaption></figure>

### Change Plan

If available on Azure Portal, the **Change Plan** action allows you to change your current outdated plan to the most recent version of the plan.

### **Recurring Billing**

If you decide to disable **Recurring billing**, your subscription will not renew automatically. Instead, Microsoft will (irreversibly) cancel the subscription towards the end of the current subscription cycle. This means, the service will be terminated automatically on that date as well. While the subscription has not expired yet, you can opt to enable **Recurring billing** at any time.

### Cancellation

* If you would like to (irreversibly) cancel your subscription, navigate to your **KONNEKT subscription** in the [Azure SaaS portal](https://portal.azure.com/#blade/HubsExtension/BrowseResourceBlade/resourceType/Microsoft.SaaS%2Fresources) and click **Cancel subscription**.

![](/files/Pckxc3RdyebcWDP9XErQ)

* If you cancel within the grace period, the service will be stopped immediately.
* If you cancel after the grace period, the service will remain active until the end of the current subscription cycle.

## Trials

In case you would like to test KONNEKT, please [request a trial via our website](https://support.konnekt.io/support/tickets/new?ticket_form=trial_request_%28konnekt%29&_gl=1) or send us an email to <sales@konnekt.io>.

## FAQs

### Why is my Microsoft Marketplace purchase not working?

You may encounter problems when purchasing through Microsoft Marketplace. Here is a list of reasons, why buying through Microsoft Marketplace may fail:

1. You do not have permissions in your Azure tenant to purchase through Microsoft Marketplace. You must be assigned the role of Owner or Contributor in the Azure subscription you want to pay with.
2. The subscription belongs to an Enterprise Agreement (EA) and the EA admin disabled Microsoft Marketplace purchases. Or the EA admin has enabled purchases only for free offers and the offer is a paid offer. Please see [here](https://learn.microsoft.com/en-us/marketplace/purchase-control-options) for details.
3. The subscription you're using belongs to a billing account in a region where the offer isn't available.\
   Our Marketplace offers are available in the following countries/regions:

   Armenia, Australia, Austria, Bulgaria, Belgium, Canada, Chile, Colombia, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, India, Indonesia, Ireland, Italy, Kenya, Latvia, Liechtenstein, Lithuania, Luxembourg, Malaysia, Malta, Monaco, Netherlands, New Zealand, Nigeria, Norway, Poland, Portugal, Puerto Rico, Romania, Saudi Arabia, Serbia, Singapore, Slovakia, Slovenia, South Africa, South Korea, Spain, Sweden, Switzerland, Taiwan, Thailand, Türkiye, United Arab Emirates, United Kingdom, United States, Vietnam
4. The subscription/billing account isn't associated with a valid payment instrument (such as a valid credit card).
5. Private Marketplace is enabled for the subscription and the offer isn't in the list of allowed offers.
6. Purchases are not permitted for subscriptions with a spending cap, including Free subscriptions, Sponsorships, and similar types.


# cleverbridge

## Prerequisites & Vendor Onboarding <a href="#prerequisites" id="prerequisites"></a>

In order to purchase KONNEKT from our merchant of record, cleverbridge GmbH (headquartered in Germany), no special prerequisites have to be met, except for accepting their terms and conditions.

Depending on your sourcing and purchasing requirements, you might have to set up cleverbridge as a vendor in your system. cleverbridge provides all relevant onboarding information [via their website](https://support.cleverbridge.com/hc/en-us/articles/4405420244243-How-do-I-register-Cleverbridge-as-a-vendor).

Should you have any questions during the onboarding process, especially in regards to legal or taxation aspects, please [contact cleverbridge directly](#for-what-inquiries-should-i-contact-cleverbridge-directly).

{% hint style="info" %}
**For US-based customers only**.

Since cleverbridge operates a local entity in the US, cleverbridge Inc., certain tax implications may arise from this. As part of their vendor [onboarding information](https://support.cleverbridge.com/hc/en-us/articles/4405449389587-I-m-a-vendor-looking-to-place-an-order-from-the-U-S-What-documents-do-I-need), they also provide a W-9 form.
{% endhint %}

## Pricing Model

KONNEKT is offered as an **annual subscription plan** with different [User Segments](#user-segments). The correct **user segment** is either

* pre-selected in case we provide a quotation or order link to you, or
* must be manually selected during checkout:<br>

  <figure><img src="/files/zotizFyh1m9QahJttzE0" alt=""><figcaption></figcaption></figure>

## Payment Options

cleverbridge provides a range of payment options (credit card, PayPal, Wire Transfer), where availability might depend on the country you are ordering from.

### Invoice-based Payments

If you require invoice-based payments, please [contact us](mailto:sales@konnekt.io) so we can provide you with a quotation or order link that provides invoice-based payments. The payment term is **30 days** **net**.

### Currencies

cleverbridge allows you to transact in a variety of currencies. The currency is automatically selected based on the location of your browser's IP address. If you would like to transact in a different currency, you can do so by selecting your preferred currency in the top right corner of the quotation or checkout site.

{% hint style="info" %}
The reference currency for KONNEKT is Euro (EUR). The forex rate cleverbridge applies when converting to other currencies is not in our control. Please note, that once an order for a subscription is placed **and** as long as **automatic renewal** is **enabled**, the forex rate is guaranteed for future renewals, i.e. cleverbridge absorbs the forex risk.
{% endhint %}

## Plan Overview

Subscriptions for KONNEKT are available based on an **annual** renewal interval.

### User Segments

The following user segments apply

<table data-header-hidden><thead><tr><th width="286.83723958333337"></th><th></th><th></th></tr></thead><tbody><tr><td><strong>User Segment</strong></td><td><strong>Minimum Total Users</strong></td><td><strong>Maximum Total Users</strong></td></tr><tr><td>KONNEKT 25 (Y)</td><td>25</td><td>249</td></tr><tr><td>KONNEKT 250 (Y)</td><td>250</td><td>999</td></tr><tr><td>KONNEKT 1000 (Y)</td><td>1,000</td><td>4,999</td></tr><tr><td>KONNEKT 5000 (Y)</td><td>5,000</td><td>9,999</td></tr><tr><td>KONNEKT 10000 (Y)</td><td>10,000</td><td>unlimited</td></tr></tbody></table>

## Subscription Management

### Self-management Portal

Cleverbridge allows you to manage any aspect of your subscription via their self-management portal, including but not limited to:

* Contact data changes
* Payment method changes
* Downloading previous invoices
* Performing user upgrades and downgrades
* Cancelling your subscription

To access the self management portal, please refer to the initial delivery / order confirmation email that was sent to you by cleverbridge at the time your order was placed. Within that email, locate the button saying **Manage Your Subscription For "\<SKU>"** and click it.

<figure><img src="/files/P7E3mnedlM2xgizLC1iW" alt=""><figcaption></figcaption></figure>

This will either navigate you to the self-management portal directly or you might have to re-generate the link (they might expire after a while) first.

{% hint style="info" %}
In case you are having difficulties accessing the self-management portal as described above, feel free to [contact cleverbridge directly](#for-what-inquiries-should-i-contact-cleverbridge-directly) for assistance by referencing your **Cleverbridge reference number**.
{% endhint %}

### User Upgrades

{% hint style="info" %}
User upgrades are only available if all previous amounts / invoices have been paid. In case you cannot pay a previous invoice before performing the upgrade, please [contact us](mailto:sales@konnekt.io).
{% endhint %}

#### Mid-term Upgrade

{% hint style="info" %}
The Mid-term Upgrade option is **available until 15 days before** your subscription is set to renew. Afterwards it will be replace by the [Early Renewal Upgrade](#early-renewal-upgrade).
{% endhint %}

If you would like to upgrade your user count, you can do so any time during the current subscription cycle by navigating to the subscription's [self-management portal](#self-management-portal) leveraging the mid-term upgrade option.

With the mid-term upgrade, additional users will be

* billed **Pro Rata Temporis**, and
* **co-termed** with the existing users,

which means you only pay for the delta in users pro-rated for the remaining subscription cycle.

To perform a mid-term upgrade,

* Navigate to the subscription's [self-management portal](#self-management-portal).
* Click **Manage products**.

<figure><img src="/files/RUg6YP9WgGNHW9ZSTmTy" alt=""><figcaption></figcaption></figure>

* Select the correct [user segment](#user-segments), and provide the new **total** number of users. The website will display the

  * upgrade price (**Upgrade price today**), and
  * the next regular renewal price assuming the new total user count (**Renewal price on ...**)

  both **including VAT**.

<figure><img src="/files/K6QwJoGRA5LfvUBKb8Mf" alt=""><figcaption></figcaption></figure>

* Click **Next**, review your **Payment method** and confirm the purchase by clicking **Buy now**.

<figure><img src="/files/cbRLWb6SullDrKVZEezi" alt=""><figcaption></figcaption></figure>

* The additional users will be added to your **existing KONNEKT license key** automatically.

#### Early Renewal Upgrade

{% hint style="info" %}
The Early Renewal Upgrade flow is **available from 15 days before** your subscription is set to renew.
{% endhint %}

If you would like to upgrade your user count as part of the next regular renewal, you can do so by navigating to the subscription's [self-management portal](#self-management-portal) leveraging the early renewal upgrade flow.

With the early renewal upgrade flow, additional users are **pre-registered** for the next regular renewal. However, you may start using the additional users immediately.

To perform an early renewal upgrade,

* Navigate to the subscription's [self-management portal](#self-management-portal).
* Click **Renew subscription**.

<figure><img src="/files/OwufXuK4MfxahFmdfnXv" alt=""><figcaption></figcaption></figure>

* Select the correct [user segment](#user-segments), and provide the new **total** number of users. The website will display the renewal price considering the additional users.

<figure><img src="/files/Jja1Ik2tmVsZ4pKPeetT" alt=""><figcaption></figcaption></figure>

* Click **Next**, review your **Payment method** and confirm the purchase by clicking **Buy now**.

<figure><img src="/files/WCDMyCZSxrUsw7xNl7MD" alt=""><figcaption></figcaption></figure>

* The additional users will be added to your **existing KONNEKT license key** automatically.

### User Downgrades

You can pre-register a reduction of your user count for the next regular renewal by leveraging the [early renewal upgrade](#early-renewal-upgrade), too. However instead of adding users, you may reduce the number of users.

### **Automatic Renewal**

{% hint style="warning" %}
Only relevant for customers buying in non-Euro currency.

By disabling Automatic Renewal you **are opting out of the perpetual forex rate** guarantee. This means the forex risk is transferred from cleverbridge to the customer.
{% endhint %}

If you decide to disable **Automatic Renewal**, your subscription will not renew automatically. Instead, cleverbridge will (irreversibly) cancel the subscription towards the end of the current subscription cycle. This means, the service will be terminated automatically on that date as well. While the subscription has not expired yet, you can opt to enable **Automatic Renewal** at any time by navigating to your subscription's [self-management portal](#self-management-portal).

<figure><img src="/files/fKnPSDg4KZNNXcBWPvnW" alt=""><figcaption></figcaption></figure>

### Cancellation

* If you would like to (irreversibly) cancel your subscription, navigate to your subscription's [self-management portal](#self-management-portal) and disable **Automatic Renewal**.
* You subscription will expire towards the end of the current cycle.
* There is **no cancellation notice period**.

## **For Partners**

Partners can leverage the same tools to manage subscriptions on behalf of their customers. To access a subscription self-management portal for a particular subscription, follow these steps:

* Sign-on to the [Partner Portal](https://www.cleverbridge.com/306/?scope=pplogin) using your partner account credentials.
* Click **History**, select **All transactions** and locate the relevant customer.
* Click the icon highlighted in below screenshot, which will re-direct you to the initial confirmation / order confirmation page:<br>

  <figure><img src="/files/1AoIey1aQGd0MIT9zNoh" alt=""><figcaption></figcaption></figure>
* On that page, locate the button saying **Manage Your Subscription For "\<SKU>"** and click it.

  <figure><img src="/files/76i6A63dYm8bh75RErD0" alt=""><figcaption></figcaption></figure>
* This will either navigate you to the self-management portal directly or you might have to re-generate the link (they might expire after a while) first.

{% hint style="info" %}
In case you are having difficulties accessing the self-management portal as described above, feel free to [contact cleverbridge directly](#for-what-inquiries-should-i-contact-cleverbridge-directly) for assistance by referencing your **Cleverbridge reference number**.
{% endhint %}

## **Trials**

In case you would like to test KONNEKT, please [request a trial via our website](https://support.konnekt.io/support/tickets/new?ticket_form=trial_request_%28konnekt%29&_gl=1) or send us an email to <sales@konnekt.io>.

## FAQs

### How to request a quote for KONNEKT?

{% hint style="info" %}
Quotes are valid for 14 days.
{% endhint %}

To request a quote for KONNEKT,

* Get in [contact with us](mailto:sales@konnekt.io) and request a quote link.
* Once we have sent the quote link to you,
  * Click it.
  * Select the correct user segment, user quantity and fill our your company information.
  * Click **Next**, review your data and click **Request price quote**.

### Why is the VAT not removed from my quote?

Cleverbridge will automatically remove the VAT if you provide a valid European VAT ID (and are not located in Germany) or a valid business registration number in countries where a VAT exemption applies (e.g. ABN in Australia).

If the VAT is not removed but you believe that you are entitled to a VAT exemption, please [contact cleverbridge directly](#for-what-inquiries-should-i-contact-cleverbridge-directly).

### How do I convert a quote into an order?

{% hint style="info" %}
Cleverbridge does not require a Purchase Order (PO) to be provided when converting a quote into an order.
{% endhint %}

To convert a quote into an order

* Locate the email that was sent you when requesting a quote
* Scroll down and locate the **Place order** button. Click it.
* Choose your preferred payment method amongst the available **Payment Options**.
* Click **Next**, review your data and confirm the purchase by clicking **Buy now**.
* The KONNEKT License Key will be generated instantaneously and sent to you via the delivery email.

### For what inquiries should I contact cleverbridge directly?

You should contact cleverbridge customer support directly, for the following inquiries:

* Taxation / VAT
* Correction of an invoice
* Issues with your payment method
* Change your contact details in the cleverbridge system

{% embed url="<https://support.cleverbridge.com/hc/en-us>" %}


# Support

## Eligibility

Customers, who have an active subscription to KONNEKT are eligible for our support services. The support is included in the subscription fee of KONNEKT.

## Scope

Our support services cover technical assistance for administrators:

* Technical questions about features of KONNEKT
* Support for incidents regarding KONNEKT

### Supported versions

We provide support exclusively for the latest release of KONNEKT as listed in our [changelog](https://docs.konnekt.io/changelog). If you experience issues while running an older version, we ask you to update to the latest release before contacting support.

KONNEKT integrates closely with Microsoft 365 and SharePoint Online and is continuously developed to stay compatible with these platforms as they evolve. In addition, security requirements change over time: what was considered safe in the past may later be identified as insecure, and we adapt the product accordingly. For these reasons, running the latest release is essential to ensure that KONNEKT works reliably and securely.

## Access

You can access our support from the help tab on our website (<https://konnekt.io>).

Using the support form will generate a ticket in our ticket system, which will be the basis for the support process. Communication will happen in written form via e-mail or web-interface of our ticket system. Depending on the support case, our support engineers may decide to arrange Microsoft Teams meetings to work on issues together with customers.

## Language

Support is provided in:

* English
* German

## Service Level

### Support hours

* Monday-Friday
* 09:00-17:00 CET / CEST
* Except for public holidays in Hesse / Germany, Christmas Eve and New Year's Eve

### Response time

Typical < 8 hours for incidents

Response time is defined as the duration between the report of the incident and the start of the incident or problem handling through one of our support engineers. The response time is to be calculated within the support hours.


