diff --git a/devices/surface/get-started.yml b/devices/surface/get-started.yml
index 131d77a578..0c309e50b7 100644
--- a/devices/surface/get-started.yml
+++ b/devices/surface/get-started.yml
@@ -72,10 +72,10 @@ landingContent:
linkLists:
- linkListType: how-to-guide
links:
+ - text: Secure Surface Dock 2 ports with Surface Enterprise Management Mode (SEMM)
+ url: secure-surface-dock-ports-semm.md
- text: Intune management of Surface UEFI settings
url: surface-manage-dfci-guide.md
- - text: Surface Enterprise Management Mode (SEMM)
- url: surface-enterprise-management-mode.md
- text: Surface Data Eraser tool
url: microsoft-surface-data-eraser.md
diff --git a/devices/surface/secure-surface-dock-ports-semm.md b/devices/surface/secure-surface-dock-ports-semm.md
index 615ba03a3c..0141a6dae1 100644
--- a/devices/surface/secure-surface-dock-ports-semm.md
+++ b/devices/surface/secure-surface-dock-ports-semm.md
@@ -91,7 +91,7 @@ Each host device must have the doc CA and two certificates as shown in Table 2.
|Provisioning administration certificate|ECC P256
SHA256|Enables you to change dock ownership and/or policy settings by allowing you to replace the CA that's currently installed on the dock.|1.3.6.1.4.1.311.76.9.21.3
1.3.6.1.4.1.311.76.9.21.4|
>[!NOTE]
- >The host authentication and provisioning certificates must be exported as.pfx files.
+ >The host authentication and provisioning certificates must be exported as .pfx files.
### Create configuration package