# Verify both sides of a Work Folders proxy publication

> Which endpoint mapping should be checked before publishing Work Folders through Web Application Proxy?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-082-verify-both-sides-of-a-work-folders-proxy-publication/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:15:49+00:00
- Modified: 2026-09-08T18:20:22+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 1 minutes

## What you need to know

Which endpoint mapping should be checked before publishing Work Folders through Web Application Proxy?

## Potentially affected

Use this review at the proxy-publication stage of the documented federation design.

## DSE recommendation

Prepare a publication map showing each external endpoint and its intended backend.

## Article

## Source facts

The documented setup installs the AD FS and Work Folders certificates in the proxy computer’s local certificate store. Publication selects an external URL, certificate, and backend URL. The wizard initially sets the backend URL equal to the external one. Microsoft calls for a separate published Work Folders application for each Work Folders server. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/storage/work-folders/deploy-work-folders-adfs-step4).

## Applicability

Use this review at the proxy-publication stage of the documented federation design. Identify the actual external name, backend server, certificate, and relying-party configuration. Check the current supported procedure before adapting the lab example.

## DSE recommendation

Prepare a publication map showing each external endpoint and its intended backend. Have the proxy and file-service owners confirm the mapping and certificate selection. Inspect the wizard’s default backend value rather than accepting it automatically. Record the access policy and the person who will accept external client behavior before publishing.

## Verification

Test an approved client connection through the external endpoint and verify which backend handles it. Compare the observed certificate and target with the publication map. For multiple servers, test each published application separately. Retain failures and mismatches as open findings before making the endpoint available to the wider client population.

## Official references

[Microsoft Learn: Deploy Work Folders with AD FS and Web Application Proxy – Step 4, Set Up Web Application Proxy](https://learn.microsoft.com/en-us/windows-server/storage/work-folders/deploy-work-folders-adfs-step4). Source reviewed September 8, 2026.

## Primary reference

- Name: Deploy Work Folders with AD FS and Web Application Proxy - Step 4, Set Up Web Application Proxy
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/storage/work-folders/deploy-work-folders-adfs-step4
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Verify both sides of a Work Folders proxy publication,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-082-verify-both-sides-of-a-work-folders-proxy-publication/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
