Root cause of error " Access denied. You do not have permission to perform this action or access this resource" - workflow - SharePoint 2013

Good evening, technet community
I hope you are doing well.
When configuring my SharePoint workflow, I encounter the problem below:
Problem Description:
Let's say my domain is: test.com, my group user is: test\group , my user is: test\user1
Except an admin account with full control at both "Web Application" and "Site Collection", all others account all have problem when creating a list item. After creating a list item, the workflow status is "cancelled" immediately
with the following message:
RequestorId: 262a35e4-99f4-40f0-929b-5d04b415f147. Details: System.ApplicationException: HTTP 401 {"Transfer-Encoding":["chunked"],"X-SharePointHealthScore":["0"],"SPClientServiceRequestDuration":["10"],"SPRequestGuid":["262a35e4-99f4-40f0-929b-5d04b415f147"],"request-id":["262a35e4-99f4-40f0-929b-5d04b415f147"],"X-FRAME-OPTIONS":["SAMEORIGIN"],"MicrosoftSharePointTeamServices":["15.0.0.4420"],"X-Content-Type-Options":["nosniff"],"X-MS-InvokeApp":["1;
RequireReadOnly"],"Cache-Control":["max-age=0, private"],"Date":["Thu, 06 Nov 2014 12:14:28 GMT"],"Server":["Microsoft-IIS\/7.5"],"WWW-Authenticate":["NTLM"],"X-AspNet-Version":["4.0.30319"],"X-Powered-By":["ASP.NET"]}
{"error":{"code":"-2147024891, System.UnauthorizedAccessException","message":{"lang":"en-US","value":"Access denied. You do not have permission to perform
this action or access this resource."}}} at Microsoft.Activities.Hosting.Runtime.Subroutine.SubroutineChild.Execute(CodeActivityContext context) at System.Activities.CodeActivity.InternalExecute(ActivityInstance instance, ActivityExecutor executor,
BookmarkManager bookmarkManager) at System.Activities.Runtime.ActivityExecutor.ExecuteActivityWorkItem.ExecuteBody(ActivityExecutor executor, BookmarkManager bookmarkManager, Location resultLocation)
- The workflow is still fail even I assign "full control" to my users group "test\group" – at Site Collection level.
Surprisingly, I have successfully found a solution for this error message. However, I still have some points that I do not clearly understand. Let's start with my solution first.
Solution:
*** i. Assign permission policy at Web Application level – Central Admin site ***
1. Central Administration ==> Application management
==> Manage Web application 
2. Go to "permission policy", then create a new permission level. This permission level contains all "edit item" permission.
3. Select "user policy", then I assign it directly to my user account: test\user1.
*** ii. Assign "edit item" permission at Site Collection level ***
1. Site Setting ==> Site permission
2. Assign "Edit" permission to my test\group.
(Actually I removed all permissions of my user group at Site Collection level. It seem my group has inherited permission from Web Application level, is that correct? )
*** iii. Create a new list item and workflow runs ……. ***
==> My question is:
1. Why I cannot assign permission to my users group - "test\group" -
 at "Web Application" level? Instead I have to assign permission policy for each users, one by one?
2. Could you please let me know how to collect full detail error message of workflow status?
Thank you very much! Have a nice weekend.

Thank you for your very detail response.
Point 1: Yes my 2 service: user profile & profile sync service are running. I performed "full synchronization" as well. Actually i've tried 3 another action plans before coming up with the solution i posted:
*** Actions completed ***
1. Activate the feature: workflow can use app permissions.
Site actions > Site Settings > Site features >activate the feature below:
 Workflows can use app permissions
2.
Refresh trusted security token services metadata feed
Get-SPTimerJob
"RefreshMetadataFeed"
| Start-SPTimerJob
- then restart the machine.
3. Start full user profile synchronization.
Point 2:
- Yes my user had Edit permission at workflow task list + list affected by workflow.
I have just remove all permissions of my user at "Site Collection" level. However, when i show my user permissions at my workflow task list and my users still have "Edit" Permission ( assigned at Web Application level. These permissions
still exist even after my workflow task list stop inheriting permission).
==> the problems probably belongs to "permission" at "Site Collection level". It seems "permission level at my Site Collection does not work". All users accounts are also suffer from the same issues except farm admin account
( which has full control at Web Application level).
I would appreciate if your guys can guide me how to make "permission" at my "Site Collection level" work again?
Thank you very much.

Similar Messages

  • Can not access CRM from outside the office network - Access denied You do not have sufficient access rights or privileges to perform this action.

    Hi,
    I can not access CRM from outside the office network - Access denied You do not have sufficient access rights or privileges to perform this action.  I can access CRM with same user id and password from our office inside the network.  I can get
    the page to give login details once I have login details I got below error. Please help me to solve this issue.  It was working before.
    Access denied You do not have sufficient access rights or privileges to perform this action. 
    Regards,
    Noushad
    [email protected]

    On Premise system Configured with AD FS server for claims-based authentication you need to update your host file with server url to access it from outside office network.
    Refer
    this on how to update host file.
    Regards, Saad

  • After Effects error: opening movie - you do not have permission to open this file (-54)

    Hi all,
    I'm new to after effects. I have just started receiving the following error every time I try to render my movie:
    "After Effects error: opening movie - you do not have permission to open this file (-54)".
    Yesterday morning, I was able to render movies, however, after I did Apple's latest update I've started receiving the following error. What is happening is that I'm trying to render a movie. It gets to a certain point in the movie (about 0;00;16;09) and then this error pops up. This morning I've tried to repair the permissions with disk utility, but that doesn't seem to have helped.
    I've searched Google and the Adobe support forums with no luck. Please help.
    Thanks in advance for you help,
    William

    Have been able to downgrade to QT 7.3 using Pacifist. Did NOT require re-install of OS.
    http://discussions.apple.com/thread...347251&tstart=0
    Download the right version here:
    http://www.apple.com/support/downloads/
    Panther: http://www.apple.com/support/downlo...forpanther.html
    Tiger: http://www.apple.com/support/downlo...31fortiger.html
    Leopard: http://www.apple.com/support/downlo...forleopard.html
    Install with Pacifist
    http://www.charlessoft.com/
    Now that I am back to QT7.3, iTunes7.6 is now asking me to update QT to 7.4 in order to be able to view the new movie rental feature of the iTunes store... which sorta sheds some light on the no permission error. Now that iTunes is renting, not just selling, movies, QT is now all fussy about ownership and permissions. Just a guess.

  • PPS Error in "IBIMonitoringAuthoring " You do not have permissions to create a data source in this document library.

    Hi,
    I am trying to use "IBIMonitoringAuthoring" in my local web site.
    But i am getting error like "Server was unable to process request. ---> You do not have permissions to create a data source in this document library.  Additional details have been logged for your administrator."
    My code is below,
     string url = ServerName + webServiceUrl;
            IBIMonitoringAuthoring biService = BIMonitoringAuthoringServiceProxy.CreateInstance(url);
            //Create data source object
            DataSource dataCube = new DataSource("AW_Data_Cube");
            dataCube.Name.Text = "AW_Data_Cube";
            dataCube.ServerName = "SQL2008dev";
            dataCube.DatabaseName = "Analysis Services Project1";
            dataCube.CubeName = "TestCube";
            dataCube.ConnectionContext = ConnectionContext.ConnectAsSharedUser;
            dataCube.FormattingDimensionName = "Measures";
            dataCube.MinutesToCache = 10;
            dataCube.CustomTimeIntelligenceSettings = "";
            biService.CreateDataSource(connectionListUrl, dataCube);
    How could i authenticate the Service. Is there any way to pass credentials for this method?
    Thanks & Regards
    Poomani Sankaran

    I suffered similar issue in Infopath, and i finally solved the issue by changing the data connection URL, it should the same as the Infopath publish location.
    for example: SP server iP 192.168.1.1 have two name, hostname is mySP, alternate assces mapping name is companySP, and you can access the websit by both
    http://mySP and
    http://companySP
    hope it can help someone..

  • I get this message on my Facebook news feed when someone posts a YouTube video. Don't know why. It's worked fine for years. I am using Safari on my iPad. If I use the Facebook app it works fine. Any thoughts. Thanks,    Access Denied   You don't have

    I get this message on my Facebook news feed when someone posts a YouTube video. Don't know why. It's worked fine for years. I am using Safari on my iPad. If I use the Facebook app it works fine. Any thoughts.
    Thanks,
    Walid
    Access Denied
    You don't have permission to access "http://fbexternal-a.akamaihd.net/embed/?" on this server.
    Reference #18.3555facd.1362007289.6945153f

    Same thing on mine, it just started happening last weekend.

  • Provider hosted App Error: You do not have permission...

    Hi everyone,
    i'm using SharePoint online. I opened a provider hosted app and when I run this I get this error:
    "Access denied. You do not have permission to perform this action or access this resource."
    when I did debug I notice that it fall in this line:
    webRequestEventArgs.WebRequestExecutor.RequestHeaders["Authorization"]
    and "webRequestEventArgs.WebRequestExecutor.RequestHeaders"
    is empty.
    what can I do?
    thank you!

    i'm trying to add an item ti my list:
    protected void Page_Load(object sender, EventArgs e)
    //constant string SharePoint principal
    string SharePointPrincipal = "00000003-0000-0ff1-ce00-000000000000";
    var contextToken = TokenHelper.GetContextTokenFromRequest(Page.Request);
    Uri hostWeb = new Uri(Page.Request["SPHostUrl"]);
    string realm = TokenHelper.GetRealmFromTargetUrl(hostWeb);
    string appOnlyAccessToken = TokenHelper.GetAppOnlyAccessToken(SharePointPrincipal, hostWeb.Authority, realm).AccessToken;
    using (ClientContext clientContext = TokenHelper.GetClientContextWithAccessToken(hostWeb.ToString(), appOnlyAccessToken))
    if (clientContext != null)
    //ShariqTest is a custom List in my SharePoint site
    var myList = clientContext.Web.Lists.GetByTitle("ListName");
    ListItemCreationInformation listItemCreate = new ListItemCreationInformation();
    Microsoft.SharePoint.Client.ListItem newItem = myList.AddItem(listItemCreate);
    newItem["ColumnName"] = "Testing ";
    newItem.Update();
    clientContext.ExecuteQuery();
     "[and the  webRequestEventArgs.WebRequestExecutor.RequestHeaders["Authorization
    is in TokenHelper.cs.
    what do you think my problem is?

  • Face Recognition Error - you don't have permission to perform this task

    Hi..
    I bought my TOSHIBA laptop from Spain, so it would be in Spanish for sure ..
    When i started the lap for the first time I tested the face recognition and other Toshiba software and they all worked .. but after two days i changed the display language to English and now i can't enter face recognition.
    It tells me "You Do not have permission to perform this task. Please contact your administrator for help" ..
    so what should i do ???

    > don't really understand the instructions going through the CMD route
    Using CMD you could enable the real Admin account but as far as I know you can uninstall the Face Recognition software in control panel -> software
    Here remove the face recognition and reboot the notebook.
    This should work too.
    >There are 2 drivers on the Toshiba website, but the latest is from 2010, did this work for you, as it didn't for me?
    It would be interesting to know the notebook model. But the latest version should work properly.
    Important is that you would remove the old version from the system firstly!

  • You do not have permission to view this directory or page using the credentials that you supplied.You do not have permission to view this directory or page using the credentials that you supplied.

    Hi,
    I update recently my OS to Yosemite and decided to use Safari again as my web browser (I was using Chrome). Some of the sites I need to access for professional reasons are not available with safari. I receive the message: "403 - Forbidden: Access is denied.You do not have permission to view this directory or page using the credentials that you supplied.". I believe there is a pattern here, they are all sites publish with IIS with SSL and build with ASP.NET.
    I can access them with Chrome (on OS X) or with Internet Explorer (with my Windows VMs).
    I've already cleared all saved passwords, cookies, history, etc...the problem remains. I'm sure this is a known problem, but all the answers I've found on the internet were for things like DNS and unavailability of the site. The sites are working fine and I can access them with Chrome.
    Can anybody help me? An explanation would also be nice :-) Something to do with Microsoft Authentication methods ?
    Thanks,

    Some websites require a special client certficate for access. If you don't have that certficate, you'll have to contact the site operator to find out how to get one.
    Sometimes the problem is caused by a web server that is configured to request an optional client certificate. Safari treats the request as mandatory. In that case, other browsers such as Firefox and Chrome may be able to connect to the site, because they ignore the request.
    The first time you were prompted for a certificate, you may have clicked through a dialog that requested access to the Apple certificate in your keychain that is used to secure the iMessage service. In that case, you may be able to regain access to the site in Safari by doing as follows.
    Back up all data.
    Double-click anywhere in the line below on this page to select it:
    com.apple.idms.appleid.prd
    Copy the selected text to the Clipboard by pressing the key combination command-C.
    Launch the Keychain Access application in any of the following ways:
    ☞ Enter the first few letters of its name into a Spotlight search. Select it in the results (it should be at the top.)
    ☞ In the Finder, select Go ▹ Utilities from the menu bar, or press the key combination shift-command-U. The application is in the folder that opens.
    ☞ Open LaunchPad. Click Utilities, then Keychain Access in the icon grid.
    Paste into the search field in the Keychain Access window by clicking in it and pressing the key combination command-V. An item may appear in the list of keychain items. The Name will begin with string you searched for, and the Kind will be "certificate."
    Delete the item by selecting it and pressing the delete key. It will be recreated automatically the next time you launch the Messages or FaceTime application.
    The next time you visit a site that prompts for an optional client certificate, cancel out of the prompt. You may have to do this several times before the server stops asking.
    Credit for this idea to Christian Braukmueller of SAP.

  • You do not have permission to view the System Landscape Directory.

    Hello there,
    When I accessed my SLD from portal, it took me to the page but kept saying:
    - You do not have permission to view the System Landscape Directory. Minimum required: UME role with permission com.sap.lcr.LcrUser and J2EE role LcrUser. See the SLD Post-Installation Guide for details
    - SLD not configured; configure the SLD in Administration first.
    I searched on these forums for the above error. Got some results, but nothing really substantial that has helped/fixed my problem.
    I also read a bit on SLD from the pdf file named: System Landscape
    Directory of SAP NetWeaver 2004s
    I also worked on the security roles and actions to individual
    users or user groups like for ex: the above pdf file advised I map the security roles from Visual Administrator, to the created roles in the portal. I've done that too. Like create a user group: 'SAP_SLD_ADMINISTRATOR'  and create a user role corresponding to it, which would be: 'LcrAdministrator'
    Then, I went to visual administrator, and clicked on 'Assign User Groups to Roles'
    Even after this, I tried to access the SLD from portal: It is still giving me the same error I mentioned above in bold italics.
    Can somebody please help me how to fix this issue?
    Thanks
    Dino.

    Graham:
    Thank you very much for making the effort to reply to my query.
    But, it still hasnt solved my problem yet.. for some reason even though I followed your instructions and did what you advised. 
    I have attached a screenshot of my Visual Administrator screen that you advised me to modify/change.
    Here it is: http://img166.imageshack.us/img166/2259/screenshot002co1.jpg
    After I made the changes, I restarted the J2EE server and went to my portal SLD page: [http://org-x:50000/sld]
    Tried authenticating usernames: LcrAdministrator and Administrator.
    Both attempts resulted in the same error show below:
    - You do not have permission to view the System Landscape Directory. Minimum required: UME role with permission com.sap.lcr.LcrUser and J2EE role LcrUser. See the SLD Post-Installation Guide for details
    - SLD not configured; configure the SLD in Administration first.
    I am wondering, if you would have another workaround regarding this issue, can you please let me know?
    Thanks
    Dino.

  • The iPhoto Library is locked, on a locked disk, or you do not have permission to make changes to it. iPhoto can try to repair the permissions.

    Hi, I have the following message when opening iPhoto:
    The iPhoto Library is locked, on a locked disk, or you do not have permission to make changes to it. iPhoto can try to repair the permissions.
    I select repair, enter my password and I get the following:
    The iPhoto Library is locked, on a locked disk, or you do not have permission to make changes to it.
    This happened a few weeks ago and I have been fumbelling around trying to fix it. I have no backup servers or shared access. My iPhone and iPad 'used to' pump pictures via iCloud but this has stopped.
    I am adminstrator with open & edit rights.
    I'm using a MacBook Air rinning OX 10.9 (Software  OS X 10.9 (13A603)
    PLEASE HELP!

    Similar problem but not quiet the same:
    Please bear with me as I am very new to this subject.
    1: Using a MacBook Air OSX 10.7.5 and it is WiFi connected to a Time Capsule.
    2: Overnight I have done a complete back-up. Checked the data files and all correct.
    3: I can open the files on the TC except for the iPhoto Library as I want to check visually that they are there. All 2,388.
    4: The iPhone Library on the TC will not allow me to look in.
    5: the iPhoto Library on the MBA allows me access and I can view etc all the 2,388.
    Q1: So why can I not look into the TC's iPhone Library? Or how do I open that library so I can look in?
    Q2: how can I export data back from the TC to the MBA if ever I needed to do that?
    Thanks for helping out a virgin in these matters.

  • You do not have permission.

    "The document xxxx could not be saved. You do not have permission."
    Why do I suddenly get this message?  I'm the only one that uses this Mac.  Permissions says I have read/write permission.  What is going on?

    geneman80 wrote:
    I seem to be having a very similar problem, I do not have permissions to write anything in MY home dir
    ls -ale
    Reset Permissions and ACL's within Home folder
    http://osxdaily.com/2011/11/15/repair-user-permissions-in-mac-os-x-lion/
    Startup holding command-r keys.
    You will boot into the Repair Utilities screen. On top, in the Menu Bar click the Utilities item then select Terminal.
    In the Terminal window, type resetpassword and hit Return.
    The Password reset utility launches, but you’re not going to reset the password. Instead, click on the icon for your Mac’s hard drive at the top. From the drop-down below it, select the user account where you are having issues.
    At the bottom of the window, you’ll see an area labeled ‘Reset Home Directory Permissions and ACLs’. Click the Reset button there.
    The reset process takes a couple of minutes. When it’s done, quit the programs you’ve opened and restart your Mac. Notice that ‘Spotlight’ starts re-indexing immediately.

  • When I login to my bank, I get the message: 403 - Forbidden: Access is denied. You do not have permission to view this directory or page using the credentials that you supplied. Have new MacBook Air with Yosemite. How to solve this problem?

    When I try to login to the website of my bank, I get the following error message:
    403 - Forbidden: Access is denied.
    You do not have permission to view this directory or page using the credentials that you supplied.
    I have a new MacBook Air with OS Yosemite installed.
    What is the problem and how can I solve it?

    Some websites require a special client certficate for access. If you don't have that certficate, you'll have to contact the site operator to find out how to get one.
    Sometimes the problem is caused by a web server that is configured to request an optional client certificate. Safari treats the request as mandatory. In that case, other browsers such as Firefox and Chrome may be able to connect to the site, because they ignore the request.
    The first time you were prompted for a certificate, you may have clicked through a dialog that requested access to the Apple certificate in your keychain that is used to secure the iMessage service. In that case, you may be able to regain access to the site in Safari by doing as follows.
    Back up all data.
    Double-click anywhere in the line below on this page to select it:
    com.apple.idms.appleid.prd
    Copy the selected text to the Clipboard by pressing the key combination command-C.
    Launch the Keychain Access application in any of the following ways:
    ☞ Enter the first few letters of its name into a Spotlight search. Select it in the results (it should be at the top.)
    ☞ In the Finder, select Go ▹ Utilities from the menu bar, or press the key combination shift-command-U. The application is in the folder that opens.
    ☞ Open LaunchPad. Click Utilities, then Keychain Access in the icon grid.
    Paste into the search field in the Keychain Access window by clicking in it and pressing the key combination command-V. An item may appear in the list of keychain items. The Name will begin with string you searched for, and the Kind will be "certificate."
    Delete the item by selecting it and pressing the delete key. It will be recreated automatically the next time you launch the Messages or FaceTime application.
    The next time you visit a site that prompts for an optional client certificate, cancel out of the prompt. You may have to do this several times before the server stops asking.
    Credit for this idea to Christian Braukmueller of SAP.

  • 403 - Forbidden: Access is denied. You do not have permission to view this directory or page using the credentials that you supplied

    I got this message when trying to checkout from a site store:
    403 - Forbidden: Access is denied.
    You do not have permission to view this directory or page using the credentials that you supplied.
    Any ideas how can I solve it?

    Ask the people running the store; that error generally means that you tried to do something they don't allow or something's wrong on their end.
    (89086)

  • Why am I getting this message: 403 - Forbidden: Access is denied. You do not have permission to view this directory or page using the credentials that you supplied?

    I just tried to access a website that I regularly access several times a day. However, this evening I received the following message: 403 - Forbidden: Access is denied.
    You do not have permission to view this directory or page using the credentials that you supplied.
    I have never seen this before, and have no idea what it means, or how to access the site. Does it have anything to do with my security settings? Help. I belong to the site, and need to access it.

    Do you need to login to access that website?
    Clear the cache and the cookies from sites that cause problems.
    * "Clear the Cache": Tools > Options > Advanced > Network > Offline Storage (Cache): "Clear Now"
    * "Remove the Cookies" from sites causing problems: Tools > Options > Privacy > Cookies: "Show Cookies"

  • While trying to access  i phone through pc (windows 7 ) showing error 'you do not have permission to access this device '

    while trying to access  i phone through pc (windows 7 ) showing error 'you do not have permission to access this device '
    And while trying  to unlock screen after lock , slide not working 'slide to unlock'

    Hello there, charialji.
    The following Knowledge Base article offers some great steps for troubleshooting your issue:
    iOS: Not responding or does not turn on
    http://support.apple.com/kb/ts3281
    Resolution
    If a single application is not responding or stops responding when it opens, you can force it to close.
    If the device is unresponsive or if certain controls aren't working as expected, restart your device.
    If the device remains unresponsive or does not turn on (or power on), reset your device.
    If there is no video or if the screen remains black, verify that the device has enough charge to turn on:
    If you are using an iPad, ensure that it's connected to the USB Power Adapter supplied with the device.
    Let it charge for at least twenty minutes, then see if it starts normally.
    If there is no image on the screen, press the Sleep/Wake button to attempt to wake the device.
    If the screen displays a red battery icon, continue charging the device until the battery is fully charged. Learn more about charging iPhone and iPod touch, or iPad.
    If the above steps do not resolve the issue, or the if the screen remains black or shows a persistent Apple logo, try restoring with iTunes:
    Connect the device to your computer and open iTunes.
    If the device appears in iTunes, select and click Restore on the Summary pane. Learn more aboutrestoring iOS software.
    If the device doesn't appear in iTunes, try to force the device into recovery mode, and then restore it.
    If the above steps do not resolve the issue, contact Apple.
    Thanks for reaching out to Apple Support Communities.
    Cheers,
    Pedro.

Maybe you are looking for

  • Nokia X6 and contacts bar re visited?

    Has anyone had any issues with the latest updates for the X6 16GB? A previous update V30 I think had the contacts bar disappearing. I was wondering if this was happening with the latest update. Any feed back would be most welcome. I had to get a new

  • Disk Error Midway through a Backup

    I am about to upgrade to Windows Vista, before doing so I wanted to Backup my itunes Library. Everything was going fine with the backup until I hit disk 5 (out of 6). Prior to it being finished I encountered a disk error, itunes gave me the option of

  • Photo wrong format iphoto

    When Im trying to import photos from my Iphone 4s to my Iphoto it says the photo format is wrong. This never happened until now. Why???

  • Share a movie that will play on Kodak M820 EasyShare Picture Frame

    I've been looking for a way to export a movie that will play on this picture frame, and although the box says it will play MOV, AVI, MPG and a few other formats, in the fine print under troubleshooting it says it might not actually play these formats

  • HP Series 1600 Printer and Printer setup utility

    I just purchased an HP 1600 printer and loaded the software When I go to add the printer in the Printer setup Utility the name shows up but it says that it can't find the drivers I have tried the fixamac software to try and fix the problem but that d