Fix SharePoint 2019 Potentially Malicious XOML Node Error
Question details
Users encounter a 'potentially malicious XOML node' error when SharePoint 2010 Designer workflows attempt to run.

- Product
- SharePoint 2019
- Device & OS
- not provided
- Scenario
- Executing SharePoint 2010 workflows involving CollectFeedbackTaskProcess after installing recent cumulative updates.
- Observed behavior
- The workflow fails to execute, and the system throws a security validation error about a potentially malicious XOML node, which is not resolved by just updating the web.config file.
Ensure you have farm administrator privileges and take a backup of your web.config and owstimer.exe.config files before making modifications.
Allow-list Activities in Configuration Files
Explicitly allow-list the workflow activities in both the web application and timer service configuration files using the correct public key token.
Recent SharePoint updates introduced stricter validation for workflow XOML files. Adding the authorizedType entries to web.config alone is insufficient; the timer service must also be updated.
Find the web.config file for your specific SharePoint web application and the owstimer.exe.config file located in the SharePoint BIN directory.
Insert the required authorizedType elements for the CollectFeedbackTaskProcess activity into both configuration files.
Replace any 'null' values in the PublicKeyToken attribute with the actual public key token of the installed assembly.
Apply the configuration changes consistently across all SharePoint servers in the farm, then run 'iisreset' from the command prompt and restart the SharePoint Timer Service via services.msc.

Apply the Latest Cumulative Update and Run PSConfig
Ensure your farm has the latest fixes installed and properly registered by running the SharePoint Configuration Wizard.
Migrate to Power Automate
Since SharePoint 2010 workflows are deprecated, migrating to a modern platform resolves legacy validation errors permanently.
Need a Reliable Office Alternative?
While resolving complex SharePoint and Microsoft ecosystem errors, you might be seeking a simpler, lightweight productivity suite. WPS Office provides a free, highly compatible alternative to Microsoft Office for your daily document needs.
- 1. Download the installer: Visit the official WPS Office website and click the free download button for your operating system.
- 2. Install WPS Office: Run the setup file and follow the quick installation prompts to deploy the suite.
- 3. Open your files: Launch WPS Office and seamlessly open your existing Office documents without losing formatting.

Frequently Asked Questions
Why am I seeing a potentially malicious XOML node error after a SharePoint update?
Recent SharePoint 2019 Cumulative Updates introduced stricter security validation for workflow XOML files. If an activity like CollectFeedbackTaskProcess is not explicitly allow-listed with the correct public key token, SharePoint blocks it for security reasons.
Where is the owstimer.exe.config file located?
The owstimer.exe.config file is typically located in the SharePoint hive under the bin directory, commonly found at C:\Program Files\Common Files\microsoft shared\Web Server Extensions\16\BIN.
Are SharePoint 2010 workflows still supported in SharePoint 2019?
No, SharePoint 2010 workflows have been deprecated and are generally unsupported in modern environments. It is strongly recommended to migrate your workflows to Power Automate or another supported platform.




