# Prepare federation certificate names before a Work Folders lab becomes production

> Which certificate planning decisions should precede the Work Folders AD FS setup example?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-059-prepare-federation-certificate-names-before-a-work-folders-lab-becomes-production/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:16:12+00:00
- Modified: 2026-09-08T18:20:21+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 1 minutes

## What you need to know

Which certificate planning decisions should precede the Work Folders AD FS setup example?

## Potentially affected

Use this review when planning the federation endpoint for the documented Work Folders design.

## DSE recommendation

Create a certificate-name worksheet before requesting issuance.

## Article

## Source facts

Microsoft’s Work Folders walkthrough starts by preparing AD FS before the later proxy and client stages. The walkthrough distinguishes its self-signed test certificate from the publicly trusted certificate recommended for production. Its certificate example includes names for the federation service, enterprise registration, and federation server. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/storage/work-folders/deploy-work-folders-adfs-step1).

## Applicability

Use this review when planning the federation endpoint for the documented Work Folders design. Identify the real service names and certificate authority. Check the procedure’s release-specific limits before adapting any historical lab instruction.

## DSE recommendation

Create a certificate-name worksheet before requesting issuance. Have the federation and certificate owners confirm which names the planned service requires and who will maintain the certificate. Keep lab identities and trust decisions visibly separate from the production request. Allow time for issuance and validation, and avoid copying sample hostnames into the deployment record.

## Verification

Inspect the issued certificate against the approved name worksheet and trust arrangement. Verify the intended federation endpoint through an authorized test before moving to later Work Folders stages. Record the certificate identity, responsible owner, and any name mismatch. Resolve the mismatch through the approved certificate process before publishing the service to clients.

## Official references

[Microsoft Learn: Deploy Work Folders with AD FS and Web Application Proxy – Step 1, Set Up AD FS](https://learn.microsoft.com/en-us/windows-server/storage/work-folders/deploy-work-folders-adfs-step1). Source reviewed September 8, 2026.

## Primary reference

- Name: Deploy Work Folders with AD FS and Web Application Proxy - Step 1, Set Up AD FS
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/storage/work-folders/deploy-work-folders-adfs-step1
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Prepare federation certificate names before a Work Folders lab becomes production,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-059-prepare-federation-certificate-names-before-a-work-folders-lab-becomes-production/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
