If you're having trouble logging into Banner Admin (dev, preprod, or production), it is often caused by your browser blocking third-party cookies or cross-site tracking. This is common with SAML authentication flows (like Microsoft Login) where the authentication redirect comes from a different domain than the application.
Follow the steps below for your browser to add an exception or adjust privacy settings and get back in.
On this page:
Method 1: Via Settings Menu
- Click the three dots (⋮) in the top right corner.
- Select Settings.
- Click Privacy and security in the left sidebar.
- Select Third-party cookies (or "Cookies and other site data").
- Scroll to "Sites that can always use cookies" (or "Allow sites to save and read cookie data").
- Click Add.
- Enter each domain one at a time, clicking Add after each entry:
- banneradmin-dev.dartmouth.edu
- banneradmin-preprod.dartmouth.edu
- banneradmin.dartmouth.edu
- login.microsoftonline.com (recommended: add the IdP domain as well)
- Close Settings. Changes save automatically.
Method 2: Via Address Bar (Brave Only)
- Type brave://settings/cookies in the address bar and press Enter.
- Scroll to "Sites allowed to use third-party cookies."
- Click Add and enter each domain listed above.
Mozilla Firefox
- Open Firefox.
- Click the three lines (≡) in the top right corner.
- Select Settings.
- Click Privacy & Security in the left sidebar.
- Scroll to Enhanced Tracking Protection.
- Under Advanced Settings
- Custom, select "Advanced Settings"
- select Custom -> Customize tracking protection
- Cookies -> Allow All cookies
- click the back arrow
- Select Manage Exceptions
- Enter each domain, clicking Allow after each entry::
- banneradmin-dev.dartmouth.edu
- banneradmin-preprod.dartmouth.edu
- banneradmin.dartmouth.edu
- login.microsoftonline.com
- Click Save Changes.
- Open Edge.
- Select Settings and more (⋯) in the upper right corner.
- Select Settings.
- Select Cookies and site permissions.
- Select Third-party cookies or Manage and delete cookies and site data.
- Under Sites that can always use cookies, select Add.
- Add each domain separately:
- banneradmin-dev.dartmouth.edu
- banneradmin-preprod.dartmouth.edu
- banneradmin.dartmouth.edu
- login.microsoftonline.com
- Close Settings. Changes save automatically.
If Application Navigator Continues Spinning
A Dartmouth signed in Edge profile can sometimes attempt Microsoft single sign-on inside the Application Navigator frame. If Microsoft requires an interactive sign-in, the Banner page may remain blank with a spinning indicator. If this happens, use a separate Edge profile for Banner:
- Select the profile icon in the upper right corner of Edge.
- Select Other profiles, then Set up new personal profile or Add profile.
- Create the profile without signing that Edge profile into a Dartmouth work or school account. You can still sign in to Dartmouth websites normally within it.
- In the new profile, open Settings, then Profiles, then Profile preferences.
- Turn off Allow single sign-on for work or school sites using this profile.
- Return to the Dartmouth Edge profile and open Settings, then Profiles, then Profile preferences.
- Under Custom site switch, select Add site.
- Add each of these hostnames separately:
- banneradmin.dartmouth.edu
- banneradmin-dev.dartmouth.edu
- banneradmin-preprod.dartmouth.edu
- For each entry, set Action to Switch and Profile name to the separate Edge profile created above.
Do not add "https://" or a page path to the custom site switch entries. Hostname only.
If Banner was previously opened in the separate profile and still spins:
- Open cookie and site data settings in that profile.
- Remove only the stored data for the affected Banner hostname and login.microsoftonline.com.
- Close and reopen Application Navigator.
- Sign in manually when prompted.
Removing this data signs the user out of those sites in that profile. In Dartmouth testing, turning off profile SSO did not repair an existing failing session by itself. Recreating the session once with SSO already disabled resolved the problem.
Guest or InPrivate Workaround
To use Guest browsing:
- Select the profile icon in the upper right corner.
- Select Other profiles, then Browse as guest.
- Go to mybanner.dartmouth.edu and sign in.
- Open Application Navigator.
A new InPrivate window can also be tried by selecting Settings and more (⋯), then New InPrivate window.
Note for Safari users: "Prevent Cross-Site Tracking" is a global setting in Safari. Unlike Chrome or Edge, Safari does not offer easy per-site exceptions for tracking prevention. If Option A below does not resolve the login issue, Option B may be needed.
On macOS
Option A: Per-Site Cookie Exception (Preferred)
- Open Safari.
- Click Safari in the top menu bar (next to the Apple logo).
- Select Settings (or "Preferences" in older versions).
- Click the Websites tab at the top.
- Select Cookies and website data in the left sidebar.
- Scroll to the "When visiting other websites" section.
- Ensure the global setting is set to "Allow from Current Website Only."
- If you have visited the Banner Admin site before, it may appear in the list below. Select it and change the setting to Allow. If the site is not in the list, visit the site first, then return to this menu to set the exception.
Option B: Disable Global Cross-Site Tracking (If Option A fails)
- Open Safari.
- Click Safari in the top menu bar.
- Select Settings (or "Preferences").
- Click the Privacy tab.
- Uncheck the box for Prevent cross-site tracking.
- Close Settings and try logging in again.
Security note: Re-enable "Prevent cross-site tracking" after your session if possible, or only leave it disabled while on a trusted network.
On iOS (iPhone/iPad)
- Open the Settings app on your device.
- Scroll down and tap Safari.
- Scroll to the Privacy & Security section.
- Toggle off Prevent Cross-Site Tracking. iOS Safari does not offer per-site exceptions for this setting, so it must be toggled globally.
- Optional but recommended if issues persist: go back to the main Settings menu, tap Safari, then Clear History and Website Data.
- Open Safari and try logging in.
- Format: Enter domains without the "https://" or "www." prefix (for example, banneradmin.dartmouth.edu).
- Restart: You may need to restart your browser for changes to take effect.
- Verification: After adding the exceptions, refresh your Banner pages and test login functionality.
- Brave Shields: If using Brave, you may also need to adjust Brave Shields for these sites by clicking the lion icon in the address bar and setting it to "Disabled" or "Standard."
- IdP Domain: For SAML logins, it is often necessary to allow cookies from the Identity Provider as well, such as login.microsoftonline.com or login.salesforce.com.
If issues persist after adding the exceptions, try the following:
- Check system date and time: SAML tokens are time sensitive. If your computer's clock is incorrect, even by a few minutes, login will fail. Ensure your system time is synchronized correctly.
- Clear cache: Clear your browser cache and cookies specifically for the Banner Admin domains.
- Incognito or Private mode: Try opening the site in an Incognito or Private window. If this works, an extension or cached cookie is likely the cause.
- Extensions: Temporarily disable any ad blockers, privacy extensions (like Privacy Badger or Ghostery), or password managers.
- Verify domain spelling: Ensure the URL matches exactly what the application requires.
- Safari specific: If using Safari and the login redirects to a blank page or loops, ensure you have cleared the Website Data for the IdP (Microsoft) as well.
External Resources
No external resources provided yet.
See Related Articles to the right for more information.