How to Fix SharePoint 2019 Workflow Failures After Security Updates
Question details
Legacy SharePoint 2010 workflows hosted on SharePoint 2019 are failing after applying a recent security update due to blocked XOML deserialization.

- Product
- SharePoint 2019
- Device & OS
- not provided
- Scenario
- Executing legacy SharePoint workflows after installing the October 2025 security patches.
- Observed behavior
- Workflows fail to run because the security update enforces an authorizedTypes allow-list for safe XOML deserialization, blocking unauthorized assemblies.
Verify that you have farm administrator privileges and prepare a non-production environment to validate the configuration file changes before applying them to your live servers.
Update the authorizedTypes Allow-list in Configuration Files
Manually add the required assembly details to the authorizedTypes allow-list in your web.config and Timer Service configuration files to bypass the deserialization block.
Recent SharePoint security updates enforce strict authorizedTypes validation to prevent unsafe XOML deserialization. Because there is no supported registry key or application setting to disable this security enforcement, you must explicitly declare the authorized types.
Use the Strong Name tool (sn.exe) with the -T parameter (e.g., sn -T YourAssembly.dll) to extract the actual public key token. Note that PublicKeyToken=null will not match a signed assembly.
Find the web.config files for the affected web applications, as well as the OWSTIMER.exe.config file used by the SharePoint Timer Service on each server.
Insert accurate authorizedType entries containing the correct assembly version, culture, public key token, namespace, and type name into the configuration files.
Ensure the updated configuration files are exactly consistent across all servers in your SharePoint 2019 farm.
Perform an IIS reset by running the 'iisreset' command, restart the SharePoint Timer Service via the Services console, and trigger a workflow to verify the fix.
Looking for a Fast, Hassle-Free Document Solution? Try WPS Office
While troubleshooting server-side SharePoint configurations requires technical effort, managing your daily documents shouldn't. WPS Office is a highly compatible, free alternative to Microsoft Office that lets you edit Word, Excel, and PowerPoint files with zero learning curve.
- 1. Download the installer: Visit the WPS Office official website and download the free version for your operating system.
- 2. Install the suite: Run the lightweight installer to quickly set up the office suite on your local machine.
- 3. Open existing files: Double-click your existing Microsoft Office documents to instantly open and edit them in WPS Office.

Frequently Asked Questions
Why did my legacy SharePoint 2010 workflows suddenly stop working in SharePoint 2019?
The October 2025 security update introduced stricter validation for unsafe XOML deserialization. It blocks workflows unless their assemblies are explicitly added to the authorizedTypes allow-list.
Can I disable the authorizedTypes allow-list enforcement?
No, there is no supported registry key or application setting to disable this security enforcement. You must manually configure the allow-list with the correct assembly details.
How do I find the correct public key token for my workflow assembly?
You can extract the actual public key token by using the Strong Name tool (sn.exe) with the -T parameter (e.g., 'sn -T YourAssembly.dll') in the Developer Command Prompt.
Which configuration files need to be modified?
You need to update the web.config file for your affected SharePoint web applications and the OWSTIMER.exe.config file used by the SharePoint Timer Service on all servers.




