{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-100-separate-work-folders-client-lab-assumptions-from-deployment-settings/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-100-separate-work-folders-client-lab-assumptions-from-deployment-settings/",
        "slug": "dse-20260908-100-separate-work-folders-client-lab-assumptions-from-deployment-settings",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-100-separate-work-folders-client-lab-assumptions-from-deployment-settings/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-100-separate-work-folders-client-lab-assumptions-from-deployment-settings.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-100-separate-work-folders-client-lab-assumptions-from-deployment-settings/"
        },
        "title": "Separate Work Folders client lab assumptions from deployment settings",
        "summary": "Which assumptions in the Work Folders client setup example must be checked before reuse?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:15:31+00:00",
        "modified_at": "2026-09-08T18:20:23+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 1,
        "word_count": 214,
        "potentially_affected": "Administrators testing Work Folders clients in an AD FS and Web Application Proxy deployment.",
        "dse_recommendation": "Document which example assumptions match the pilot and which will be replaced by approved production settings.",
        "primary_source": {
            "name": "Deploy Work Folders with AD FS and Web Application Proxy - Step 5, Set Up Clients",
            "url": "https://learn.microsoft.com/en-us/windows-server/storage/work-folders/deploy-work-folders-adfs-step5",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft’s procedure sets up both domain-member and non-domain Windows clients to test synchronization between their Work Folders. The example installs previously created AD FS and Work Folders certificates in the domain client’s computer certificate store. For the non-domain test client, it changes the hosts file because the example did not create public DNS records. That instruction is explicitly a test-environment assumption. <a href=\"https://learn.microsoft.com/en-us/windows-server/storage/work-folders/deploy-work-folders-adfs-step5\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft documentation</a>.</p>\n<h2>Applicability</h2>\n<p>Identify the client join state, actual service names, certificate chain, and name-resolution arrangement. Review the preceding deployment steps before treating this final client step as a complete service installation.</p>\n<h2>DSE recommendation</h2>\n<p>Document which example assumptions match the pilot and which will be replaced by approved production settings. Have the identity and network owners confirm the service names and certificate trust path. Keep sample addresses and test-only hosts entries out of the general client rollout instructions.</p>\n<h2>Verification</h2>\n<p>Configure representative clients through the approved route, then synchronize a controlled file in each direction. Record the service name contacted, certificate result, and observed file state on both clients. Repeat from the intended network locations, and investigate a DNS or trust exception before calling the client setup complete.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/storage/work-folders/deploy-work-folders-adfs-step5\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Deploy Work Folders with AD FS and Web Application Proxy &#8211; Step 5, Set Up Clients</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nMicrosoft’s procedure sets up both domain-member and non-domain Windows clients to test synchronization between their Work Folders. The example installs previously created AD FS and Work Folders certificates in the domain client’s computer certificate store. For the non-domain test client, it changes the hosts file because the example did not create public DNS records. That instruction is explicitly a test-environment assumption. Microsoft documentation.\nApplicability\nIdentify the client join state, actual service names, certificate chain, and name-resolution arrangement. Review the preceding deployment steps before treating this final client step as a complete service installation.\nDSE recommendation\nDocument which example assumptions match the pilot and which will be replaced by approved production settings. Have the identity and network owners confirm the service names and certificate trust path. Keep sample addresses and test-only hosts entries out of the general client rollout instructions.\nVerification\nConfigure representative clients through the approved route, then synchronize a controlled file in each direction. Record the service name contacted, certificate result, and observed file state on both clients. Repeat from the intended network locations, and investigate a DNS or trust exception before calling the client setup complete.\nOfficial references\nMicrosoft Learn: Deploy Work Folders with AD FS and Web Application Proxy – Step 5, Set Up Clients. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nMicrosoft’s procedure sets up both domain-member and non-domain Windows clients to test synchronization between their Work Folders. The example installs previously created AD FS and Work Folders certificates in the domain client’s computer certificate store. For the non-domain test client, it changes the hosts file because the example did not create public DNS records. That instruction is explicitly a test-environment assumption. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/storage/work-folders/deploy-work-folders-adfs-step5).\n\n## Applicability\n\nIdentify the client join state, actual service names, certificate chain, and name-resolution arrangement. Review the preceding deployment steps before treating this final client step as a complete service installation.\n\n## DSE recommendation\n\nDocument which example assumptions match the pilot and which will be replaced by approved production settings. Have the identity and network owners confirm the service names and certificate trust path. Keep sample addresses and test-only hosts entries out of the general client rollout instructions.\n\n## Verification\n\nConfigure representative clients through the approved route, then synchronize a controlled file in each direction. Record the service name contacted, certificate result, and observed file state on both clients. Repeat from the intended network locations, and investigate a DNS or trust exception before calling the client setup complete.\n\n## Official references\n\n[Microsoft Learn: Deploy Work Folders with AD FS and Web Application Proxy – Step 5, Set Up Clients](https://learn.microsoft.com/en-us/windows-server/storage/work-folders/deploy-work-folders-adfs-step5). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-100-separate-work-folders-client-lab-assumptions-from-deployment-settings/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-100-separate-work-folders-client-lab-assumptions-from-deployment-settings/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-100-separate-work-folders-client-lab-assumptions-from-deployment-settings/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Separate Work Folders client lab assumptions from deployment settings",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-100-separate-work-folders-client-lab-assumptions-from-deployment-settings/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-100-separate-work-folders-client-lab-assumptions-from-deployment-settings/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-100-separate-work-folders-client-lab-assumptions-from-deployment-settings/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-100-separate-work-folders-client-lab-assumptions-from-deployment-settings/",
                "headline": "Separate Work Folders client lab assumptions from deployment settings",
                "description": "Which assumptions in the Work Folders client setup example must be checked before reuse?",
                "abstract": "Which assumptions in the Work Folders client setup example must be checked before reuse?",
                "articleBody": "Source facts\nMicrosoft’s procedure sets up both domain-member and non-domain Windows clients to test synchronization between their Work Folders. The example installs previously created AD FS and Work Folders certificates in the domain client’s computer certificate store. For the non-domain test client, it changes the hosts file because the example did not create public DNS records. That instruction is explicitly a test-environment assumption. Microsoft documentation.\nApplicability\nIdentify the client join state, actual service names, certificate chain, and name-resolution arrangement. Review the preceding deployment steps before treating this final client step as a complete service installation.\nDSE recommendation\nDocument which example assumptions match the pilot and which will be replaced by approved production settings. Have the identity and network owners confirm the service names and certificate trust path. Keep sample addresses and test-only hosts entries out of the general client rollout instructions.\nVerification\nConfigure representative clients through the approved route, then synchronize a controlled file in each direction. Record the service name contacted, certificate result, and observed file state on both clients. Repeat from the intended network locations, and investigate a DNS or trust exception before calling the client setup complete.\nOfficial references\nMicrosoft Learn: Deploy Work Folders with AD FS and Web Application Proxy – Step 5, Set Up Clients. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:15:31+00:00",
                "dateModified": "2026-09-08T18:20:23+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-100-separate-work-folders-client-lab-assumptions-from-deployment-settings/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-100-separate-work-folders-client-lab-assumptions-from-deployment-settings/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Separate Work Folders client lab assumptions from deployment settings"
                },
                "articleSection": [
                    "IT",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "IT",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 214,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Deploy Work Folders with AD FS and Web Application Proxy - Step 5, Set Up Clients",
                    "url": "https://learn.microsoft.com/en-us/windows-server/storage/work-folders/deploy-work-folders-adfs-step5"
                }
            }
        ]
    }
}