logo
search
Security Policy Errors

How to Fix SharePoint 2019 Workflow Failures After Security Updates

Aamir Naveed AkramAamir Naveed Akram Sep 29, 2026 869 views

Question details

Legacy SharePoint 2010 workflows hosted on SharePoint 2019 are failing after applying a recent security update due to blocked XOML deserialization.

Fixing SharePoint 2019 Workflow Failures After Security Updates
Product
SharePoint 2019
Device & OS
not provided
Scenario
Executing legacy SharePoint workflows after installing the October 2025 security patches.
Observed behavior
Workflows fail to run because the security update enforces an authorizedTypes allow-list for safe XOML deserialization, blocking unauthorized assemblies.
Before you start

Verify that you have farm administrator privileges and prepare a non-production environment to validate the configuration file changes before applying them to your live servers.

Solution 1Recommended

Update the authorizedTypes Allow-list in Configuration Files

Manually add the required assembly details to the authorizedTypes allow-list in your web.config and Timer Service configuration files to bypass the deserialization block.

Recent SharePoint security updates enforce strict authorizedTypes validation to prevent unsafe XOML deserialization. Because there is no supported registry key or application setting to disable this security enforcement, you must explicitly declare the authorized types.

1
Verify the public key token

Use the Strong Name tool (sn.exe) with the -T parameter (e.g., sn -T YourAssembly.dll) to extract the actual public key token. Note that PublicKeyToken=null will not match a signed assembly.

2
Locate configuration files

Find the web.config files for the affected web applications, as well as the OWSTIMER.exe.config file used by the SharePoint Timer Service on each server.

3
Add authorizedType entries

Insert accurate authorizedType entries containing the correct assembly version, culture, public key token, namespace, and type name into the configuration files.

4
Replicate across the farm

Ensure the updated configuration files are exactly consistent across all servers in your SharePoint 2019 farm.

5
Restart services and test

Perform an IIS reset by running the 'iisreset' command, restart the SharePoint Timer Service via the Services console, and trigger a workflow to verify the fix.

Retain Security Updates: Do not roll back or uninstall the security updates, as they contain critical security fixes for your SharePoint environment.
Free Microsoft Office alternative

Looking for a Fast, Hassle-Free Document Solution? Try WPS Office

While troubleshooting server-side SharePoint configurations requires technical effort, managing your daily documents shouldn't. WPS Office is a highly compatible, free alternative to Microsoft Office that lets you edit Word, Excel, and PowerPoint files with zero learning curve.

  1. 1. Download the installer: Visit the WPS Office official website and download the free version for your operating system.
  2. 2. Install the suite: Run the lightweight installer to quickly set up the office suite on your local machine.
  3. 3. Open existing files: Double-click your existing Microsoft Office documents to instantly open and edit them in WPS Office.
Seamlessly edit Microsoft Office formats (.docx, .xlsx, .pptx) with full compatibility.Free and lightweight, requiring minimal system resources compared to heavy enterprise tools.Familiar tabbed interface making migration simple for all users.Built-in PDF editing and seamless cloud synchronization.
microsoft office alternative - wps office

Frequently Asked Questions

Why did my legacy SharePoint 2010 workflows suddenly stop working in SharePoint 2019?

The October 2025 security update introduced stricter validation for unsafe XOML deserialization. It blocks workflows unless their assemblies are explicitly added to the authorizedTypes allow-list.

Can I disable the authorizedTypes allow-list enforcement?

No, there is no supported registry key or application setting to disable this security enforcement. You must manually configure the allow-list with the correct assembly details.

How do I find the correct public key token for my workflow assembly?

You can extract the actual public key token by using the Strong Name tool (sn.exe) with the -T parameter (e.g., 'sn -T YourAssembly.dll') in the Developer Command Prompt.

Which configuration files need to be modified?

You need to update the web.config file for your affected SharePoint web applications and the OWSTIMER.exe.config file used by the SharePoint Timer Service on all servers.