# Complete the Work Folders relying-party configuration beyond the AD FS wizard

> What remains to be reviewed after the Work Folders relying-party trust is created?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-072-complete-the-work-folders-relying-party-configuration-beyond-the-ad-fs-wizard/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:15:59+00:00
- Modified: 2026-09-08T18:20:22+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 1 minutes

## What you need to know

What remains to be reviewed after the Work Folders relying-party trust is created?

## Potentially affected

Use this review for the documented Work Folders federation workflow.

## DSE recommendation

Prepare an object-level checklist separating the displayed trust name, service identifier, claim rules, and additional PowerShell settings.

## Article

## Source facts

Microsoft requires a Work Folders relying-party trust for AD FS integration and permits creating it before Work Folders itself is configured. The documented Work Folders relying-party identifier is fixed by the service rather than being an arbitrary display name. The procedure also requires options configured through PowerShell that the wizard interface does not expose. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/storage/work-folders/deploy-work-folders-adfs-step2).

## Applicability

Use this review for the documented Work Folders federation workflow. Identify the actual relying-party object and the applicable server release. Review the complete source procedure before choosing its access and claim settings.

## DSE recommendation

Prepare an object-level checklist separating the displayed trust name, service identifier, claim rules, and additional PowerShell settings. Have the federation owner review the intended access policy instead of copying lab permissions without a decision. Record which administrator completed each portion and preserve the previous trust configuration through the approved change process.

## Verification

Inspect the resulting trust properties and compare them with the chosen procedure. Test an approved Work Folders authentication flow and retain the relevant failure or success context. Investigate a wizard-completion result that lacks the required additional settings. Close the configuration only after the federation and file-service owners accept the same tested object.

## Official references

[Microsoft Learn: Deploy Work Folders with AD FS and Web Application Proxy – Step 2, AD FS Post-Configuration Work](https://learn.microsoft.com/en-us/windows-server/storage/work-folders/deploy-work-folders-adfs-step2). Source reviewed September 8, 2026.

## Primary reference

- Name: Deploy Work Folders with AD FS and Web Application Proxy - Step 2, AD FS Post-Configuration Work
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/storage/work-folders/deploy-work-folders-adfs-step2
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Complete the Work Folders relying-party configuration beyond the AD FS wizard,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-072-complete-the-work-folders-relying-party-configuration-beyond-the-ad-fs-wizard/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
