401 Error on Get Identity Workflow Action

We are currently experiencing an issue with a workflow that had been active and working as expected until yesterday, August 13th.

The workflow suddenly started returning a 401 Unauthorized error during a Get Identity action. This is a native SailPoint Workflow action and does not require any credentials or authentication configuration within the step itself.

What makes this behavior unusual is that the workflow was previously running without any issues. Additionally, there is another Get Identity action earlier in the same workflow that continues to execute successfully, while this specific step consistently returns the 401 error.

Could you please assist us in identifying what could be causing this behavior, considering that no changes were made to the authentication configuration and the workflow was previously working as expected?

Hello @Luan ,

For Workflow actions such as Get Identity, Get Access, Manage Access, etc., the action implicitly use the permissions/context of the workflow owner.

Could you check whether the workflow owner is still active in ISC and whether their access or permissions have changed recently?

Hello Ousmane,

The workflow owner is an active service identity in ISC and currently has Org Admin. We have also confirmed that its access and permissions have not been changed.

Additionally, there is another Get Identity action earlier in the same workflow that executes successfully. The 401 Unauthorized error occurs only on the second Get Identity action.

Hi Luan,

I had the same initial thought as @baoussounda but the first Get Identity continues to work. Since this is something that was working, and now is not, that sounds like it qualifies as a support case. I’d like to be able to offer more of an explanation but I think that’s the best direction for now.

Matt

Hi Matt,

I already have a support case open regarding this issue, but I also decided to post it here in case someone in the community had encountered the same behavior and could provide a quicker solution or additional insight.

In any case, once I receive a solution or further clarification from the Support team, I’ll update this thread so that anyone who encounters the same issue in the future can use it as a reference.

Thank you all for your time and support!

Hello Luan. I recently ran into a very similar issue in one of my workflows. A Get Identity action that had been working fine suddenly started failing with 401 Unauthorized. In my case, the workflow owner was still active, had the required permissions, and nothing had changed on our side either.

What fixed it for me was:

  1. Disable the workflow.
  2. Change the workflow owner to another Org Admin and save it.
  3. Change the owner back to the original owner.
  4. Re-enable the workflow and test it again.

After that, the workflow executed normally again with no 401. I have attached a screenshot from my case for reference. This was the same 401 I was getting on the Get Identity action before changing the workflow owner.

This also lines up with SailPoint’s documentation. A workflow has a personal access token associated with its owner, and assigning the workflow to another admin generates a new token (Building Workflows). The workflow must be disabled before changing the owner (Managing Workflows).

There is also a very similar Get Identity 401 issue where changing the workflow owner resolved it (related thread).

Since you have already confirmed that the owner is active with Org Admin and nothing changed before this started happening, I would give this a try and see if it clears the 401.

Hi @Luan can you change the workflow owner and assign that workflow owner who is having admin rights can you try that

Hi everyone,

Just updating this topic with the solution I found.

This workflow was working correctly before, so I believe there may have been some update in Workflows that changed the behavior of the Get Identity step when it receives an empty input.

In my case, an empty value was an expected scenario, but the step started returning a 401 error instead of allowing the workflow to continue.

The solution was to add error handling to the Get Identity step. This way, when the input is empty and the step fails, the workflow follows the error path and continues through the logic that handles the case where no identity exists.

It solved the issue for me, although I still find the 401 response misleading for this scenario.