{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-072-complete-the-work-folders-relying-party-configuration-beyond-the-ad-fs-wizard/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-072-complete-the-work-folders-relying-party-configuration-beyond-the-ad-fs-wizard/",
        "slug": "dse-20260908-072-complete-the-work-folders-relying-party-configuration-beyond-the-ad-fs-wizard",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-072-complete-the-work-folders-relying-party-configuration-beyond-the-ad-fs-wizard/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-072-complete-the-work-folders-relying-party-configuration-beyond-the-ad-fs-wizard.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-072-complete-the-work-folders-relying-party-configuration-beyond-the-ad-fs-wizard/"
        },
        "title": "Complete the Work Folders relying-party configuration beyond the AD FS wizard",
        "summary": "What remains to be reviewed after the Work Folders relying-party trust is created?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:15:59+00:00",
        "modified_at": "2026-09-08T18:20:22+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 1,
        "word_count": 220,
        "potentially_affected": "Use this review for the documented Work Folders federation workflow.",
        "dse_recommendation": "Prepare an object-level checklist separating the displayed trust name, service identifier, claim rules, and additional PowerShell settings.",
        "primary_source": {
            "name": "Deploy Work Folders with AD FS and Web Application Proxy - Step 2, AD FS Post-Configuration Work",
            "url": "https://learn.microsoft.com/en-us/windows-server/storage/work-folders/deploy-work-folders-adfs-step2",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft requires a Work Folders relying-party trust for AD FS integration and permits creating it before Work Folders itself is configured. The documented Work Folders relying-party identifier is fixed by the service rather than being an arbitrary display name. The procedure also requires options configured through PowerShell that the wizard interface does not expose. <a href=\"https://learn.microsoft.com/en-us/windows-server/storage/work-folders/deploy-work-folders-adfs-step2\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft documentation</a>.</p>\n<h2>Applicability</h2>\n<p>Use this review for the documented Work Folders federation workflow. Identify the actual relying-party object and the applicable server release. Review the complete source procedure before choosing its access and claim settings.</p>\n<h2>DSE recommendation</h2>\n<p>Prepare an object-level checklist separating the displayed trust name, service identifier, claim rules, and additional PowerShell settings. Have the federation owner review the intended access policy instead of copying lab permissions without a decision. Record which administrator completed each portion and preserve the previous trust configuration through the approved change process.</p>\n<h2>Verification</h2>\n<p>Inspect the resulting trust properties and compare them with the chosen procedure. Test an approved Work Folders authentication flow and retain the relevant failure or success context. Investigate a wizard-completion result that lacks the required additional settings. Close the configuration only after the federation and file-service owners accept the same tested object.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/storage/work-folders/deploy-work-folders-adfs-step2\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Deploy Work Folders with AD FS and Web Application Proxy &#8211; Step 2, AD FS Post-Configuration Work</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nMicrosoft requires a Work Folders relying-party trust for AD FS integration and permits creating it before Work Folders itself is configured. The documented Work Folders relying-party identifier is fixed by the service rather than being an arbitrary display name. The procedure also requires options configured through PowerShell that the wizard interface does not expose. Microsoft documentation.\nApplicability\nUse this review for the documented Work Folders federation workflow. Identify the actual relying-party object and the applicable server release. Review the complete source procedure before choosing its access and claim settings.\nDSE recommendation\nPrepare an object-level checklist separating the displayed trust name, service identifier, claim rules, and additional PowerShell settings. Have the federation owner review the intended access policy instead of copying lab permissions without a decision. Record which administrator completed each portion and preserve the previous trust configuration through the approved change process.\nVerification\nInspect the resulting trust properties and compare them with the chosen procedure. Test an approved Work Folders authentication flow and retain the relevant failure or success context. Investigate a wizard-completion result that lacks the required additional settings. Close the configuration only after the federation and file-service owners accept the same tested object.\nOfficial references\nMicrosoft Learn: Deploy Work Folders with AD FS and Web Application Proxy – Step 2, AD FS Post-Configuration Work. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nMicrosoft requires a Work Folders relying-party trust for AD FS integration and permits creating it before Work Folders itself is configured. The documented Work Folders relying-party identifier is fixed by the service rather than being an arbitrary display name. The procedure also requires options configured through PowerShell that the wizard interface does not expose. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/storage/work-folders/deploy-work-folders-adfs-step2).\n\n## Applicability\n\nUse this review for the documented Work Folders federation workflow. Identify the actual relying-party object and the applicable server release. Review the complete source procedure before choosing its access and claim settings.\n\n## DSE recommendation\n\nPrepare an object-level checklist separating the displayed trust name, service identifier, claim rules, and additional PowerShell settings. Have the federation owner review the intended access policy instead of copying lab permissions without a decision. Record which administrator completed each portion and preserve the previous trust configuration through the approved change process.\n\n## Verification\n\nInspect the resulting trust properties and compare them with the chosen procedure. Test an approved Work Folders authentication flow and retain the relevant failure or success context. Investigate a wizard-completion result that lacks the required additional settings. Close the configuration only after the federation and file-service owners accept the same tested object.\n\n## Official references\n\n[Microsoft Learn: Deploy Work Folders with AD FS and Web Application Proxy – Step 2, AD FS Post-Configuration Work](https://learn.microsoft.com/en-us/windows-server/storage/work-folders/deploy-work-folders-adfs-step2). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-072-complete-the-work-folders-relying-party-configuration-beyond-the-ad-fs-wizard/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-072-complete-the-work-folders-relying-party-configuration-beyond-the-ad-fs-wizard/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-072-complete-the-work-folders-relying-party-configuration-beyond-the-ad-fs-wizard/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Complete the Work Folders relying-party configuration beyond the AD FS wizard",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-072-complete-the-work-folders-relying-party-configuration-beyond-the-ad-fs-wizard/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-072-complete-the-work-folders-relying-party-configuration-beyond-the-ad-fs-wizard/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-072-complete-the-work-folders-relying-party-configuration-beyond-the-ad-fs-wizard/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-072-complete-the-work-folders-relying-party-configuration-beyond-the-ad-fs-wizard/",
                "headline": "Complete the Work Folders relying-party configuration beyond the AD FS wizard",
                "description": "What remains to be reviewed after the Work Folders relying-party trust is created?",
                "abstract": "What remains to be reviewed after the Work Folders relying-party trust is created?",
                "articleBody": "Source facts\nMicrosoft requires a Work Folders relying-party trust for AD FS integration and permits creating it before Work Folders itself is configured. The documented Work Folders relying-party identifier is fixed by the service rather than being an arbitrary display name. The procedure also requires options configured through PowerShell that the wizard interface does not expose. Microsoft documentation.\nApplicability\nUse this review for the documented Work Folders federation workflow. Identify the actual relying-party object and the applicable server release. Review the complete source procedure before choosing its access and claim settings.\nDSE recommendation\nPrepare an object-level checklist separating the displayed trust name, service identifier, claim rules, and additional PowerShell settings. Have the federation owner review the intended access policy instead of copying lab permissions without a decision. Record which administrator completed each portion and preserve the previous trust configuration through the approved change process.\nVerification\nInspect the resulting trust properties and compare them with the chosen procedure. Test an approved Work Folders authentication flow and retain the relevant failure or success context. Investigate a wizard-completion result that lacks the required additional settings. Close the configuration only after the federation and file-service owners accept the same tested object.\nOfficial references\nMicrosoft Learn: Deploy Work Folders with AD FS and Web Application Proxy – Step 2, AD FS Post-Configuration Work. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:15:59+00:00",
                "dateModified": "2026-09-08T18:20:22+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-072-complete-the-work-folders-relying-party-configuration-beyond-the-ad-fs-wizard/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-072-complete-the-work-folders-relying-party-configuration-beyond-the-ad-fs-wizard/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Complete the Work Folders relying-party configuration beyond the AD FS wizard"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 220,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Deploy Work Folders with AD FS and Web Application Proxy - Step 2, AD FS Post-Configuration Work",
                    "url": "https://learn.microsoft.com/en-us/windows-server/storage/work-folders/deploy-work-folders-adfs-step2"
                }
            }
        ]
    }
}