Additional Microsoft Entra services and features related to identity, access, and network security
You might consider splitting the policy into two—one that enforces APP for supported apps and another that applies other restrictions (such as MFA or compliant device) for SharePoint Online (which will implicitly allow Web Client Extensibility).
If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.
hth
Marcin