{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-082-verify-both-sides-of-a-work-folders-proxy-publication/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-082-verify-both-sides-of-a-work-folders-proxy-publication/",
        "slug": "dse-20260908-082-verify-both-sides-of-a-work-folders-proxy-publication",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-082-verify-both-sides-of-a-work-folders-proxy-publication/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-082-verify-both-sides-of-a-work-folders-proxy-publication.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-082-verify-both-sides-of-a-work-folders-proxy-publication/"
        },
        "title": "Verify both sides of a Work Folders proxy publication",
        "summary": "Which endpoint mapping should be checked before publishing Work Folders through Web Application Proxy?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:15:49+00:00",
        "modified_at": "2026-09-08T18:20:22+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 1,
        "word_count": 218,
        "potentially_affected": "Use this review at the proxy-publication stage of the documented federation design.",
        "dse_recommendation": "Prepare a publication map showing each external endpoint and its intended backend.",
        "primary_source": {
            "name": "Deploy Work Folders with AD FS and Web Application Proxy - Step 4, Set Up Web Application Proxy",
            "url": "https://learn.microsoft.com/en-us/windows-server/storage/work-folders/deploy-work-folders-adfs-step4",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>The documented setup installs the AD FS and Work Folders certificates in the proxy computer&#8217;s local certificate store. Publication selects an external URL, certificate, and backend URL. The wizard initially sets the backend URL equal to the external one. Microsoft calls for a separate published Work Folders application for each Work Folders server. <a href=\"https://learn.microsoft.com/en-us/windows-server/storage/work-folders/deploy-work-folders-adfs-step4\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft documentation</a>.</p>\n<h2>Applicability</h2>\n<p>Use this review at the proxy-publication stage of the documented federation design. Identify the actual external name, backend server, certificate, and relying-party configuration. Check the current supported procedure before adapting the lab example.</p>\n<h2>DSE recommendation</h2>\n<p>Prepare a publication map showing each external endpoint and its intended backend. Have the proxy and file-service owners confirm the mapping and certificate selection. Inspect the wizard&#8217;s default backend value rather than accepting it automatically. Record the access policy and the person who will accept external client behavior before publishing.</p>\n<h2>Verification</h2>\n<p>Test an approved client connection through the external endpoint and verify which backend handles it. Compare the observed certificate and target with the publication map. For multiple servers, test each published application separately. Retain failures and mismatches as open findings before making the endpoint available to the wider client population.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/storage/work-folders/deploy-work-folders-adfs-step4\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Deploy Work Folders with AD FS and Web Application Proxy &#8211; Step 4, Set Up Web Application Proxy</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nThe documented setup installs the AD FS and Work Folders certificates in the proxy computer’s local certificate store. Publication selects an external URL, certificate, and backend URL. The wizard initially sets the backend URL equal to the external one. Microsoft calls for a separate published Work Folders application for each Work Folders server. Microsoft documentation.\nApplicability\nUse this review at the proxy-publication stage of the documented federation design. Identify the actual external name, backend server, certificate, and relying-party configuration. Check the current supported procedure before adapting the lab example.\nDSE recommendation\nPrepare a publication map showing each external endpoint and its intended backend. Have the proxy and file-service owners confirm the mapping and certificate selection. Inspect the wizard’s default backend value rather than accepting it automatically. Record the access policy and the person who will accept external client behavior before publishing.\nVerification\nTest an approved client connection through the external endpoint and verify which backend handles it. Compare the observed certificate and target with the publication map. For multiple servers, test each published application separately. Retain failures and mismatches as open findings before making the endpoint available to the wider client population.\nOfficial references\nMicrosoft Learn: Deploy Work Folders with AD FS and Web Application Proxy – Step 4, Set Up Web Application Proxy. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nThe documented setup installs the AD FS and Work Folders certificates in the proxy computer’s local certificate store. Publication selects an external URL, certificate, and backend URL. The wizard initially sets the backend URL equal to the external one. Microsoft calls for a separate published Work Folders application for each Work Folders server. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/storage/work-folders/deploy-work-folders-adfs-step4).\n\n## Applicability\n\nUse this review at the proxy-publication stage of the documented federation design. Identify the actual external name, backend server, certificate, and relying-party configuration. Check the current supported procedure before adapting the lab example.\n\n## DSE recommendation\n\nPrepare a publication map showing each external endpoint and its intended backend. Have the proxy and file-service owners confirm the mapping and certificate selection. Inspect the wizard’s default backend value rather than accepting it automatically. Record the access policy and the person who will accept external client behavior before publishing.\n\n## Verification\n\nTest an approved client connection through the external endpoint and verify which backend handles it. Compare the observed certificate and target with the publication map. For multiple servers, test each published application separately. Retain failures and mismatches as open findings before making the endpoint available to the wider client population.\n\n## Official references\n\n[Microsoft Learn: Deploy Work Folders with AD FS and Web Application Proxy – Step 4, Set Up Web Application Proxy](https://learn.microsoft.com/en-us/windows-server/storage/work-folders/deploy-work-folders-adfs-step4). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-082-verify-both-sides-of-a-work-folders-proxy-publication/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-082-verify-both-sides-of-a-work-folders-proxy-publication/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-082-verify-both-sides-of-a-work-folders-proxy-publication/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Verify both sides of a Work Folders proxy publication",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-082-verify-both-sides-of-a-work-folders-proxy-publication/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-082-verify-both-sides-of-a-work-folders-proxy-publication/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-082-verify-both-sides-of-a-work-folders-proxy-publication/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-082-verify-both-sides-of-a-work-folders-proxy-publication/",
                "headline": "Verify both sides of a Work Folders proxy publication",
                "description": "Which endpoint mapping should be checked before publishing Work Folders through Web Application Proxy?",
                "abstract": "Which endpoint mapping should be checked before publishing Work Folders through Web Application Proxy?",
                "articleBody": "Source facts\nThe documented setup installs the AD FS and Work Folders certificates in the proxy computer’s local certificate store. Publication selects an external URL, certificate, and backend URL. The wizard initially sets the backend URL equal to the external one. Microsoft calls for a separate published Work Folders application for each Work Folders server. Microsoft documentation.\nApplicability\nUse this review at the proxy-publication stage of the documented federation design. Identify the actual external name, backend server, certificate, and relying-party configuration. Check the current supported procedure before adapting the lab example.\nDSE recommendation\nPrepare a publication map showing each external endpoint and its intended backend. Have the proxy and file-service owners confirm the mapping and certificate selection. Inspect the wizard’s default backend value rather than accepting it automatically. Record the access policy and the person who will accept external client behavior before publishing.\nVerification\nTest an approved client connection through the external endpoint and verify which backend handles it. Compare the observed certificate and target with the publication map. For multiple servers, test each published application separately. Retain failures and mismatches as open findings before making the endpoint available to the wider client population.\nOfficial references\nMicrosoft Learn: Deploy Work Folders with AD FS and Web Application Proxy – Step 4, Set Up Web Application Proxy. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:15:49+00:00",
                "dateModified": "2026-09-08T18:20:22+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-082-verify-both-sides-of-a-work-folders-proxy-publication/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-082-verify-both-sides-of-a-work-folders-proxy-publication/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Verify both sides of a Work Folders proxy publication"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 218,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Deploy Work Folders with AD FS and Web Application Proxy - Step 4, Set Up Web Application Proxy",
                    "url": "https://learn.microsoft.com/en-us/windows-server/storage/work-folders/deploy-work-folders-adfs-step4"
                }
            }
        ]
    }
}