Direct answer
To enable cookies, allow the affected site to save on-device site data, then add a third-party cookie exception only if the broken flow uses an embedded login, payment, document editor, chat widget, or LMS frame. Start with the Cookie Test; it verifies that this tab can set and read first-party cookies. Then run the Storage Test to catch related localStorage, sessionStorage, and IndexedDB blocks.
Use the smallest fix that makes the test pass:
- Allow first-party cookies and site data for the site.
- Clear only that site's stale cookies if the setting is already allowed.
- Add a third-party exception only for trusted cross-site flows.
- Re-run the test before changing another setting.
If the problem is an SSO loop or checkout iframe, keep this guide open and also use Third-party cookies blocked: what breaks and how to fix it safely.
What the tests tell you
The Cookie Test does a real write-read check. It is more useful than a settings page that only says cookies are "allowed."

Use the flow to move from a failing Cookie Test result to the narrowest browser setting change, then verify before changing another control.
- Cookies enabled: no means the browser, a profile setting, private mode, or policy is blocking cookies before the site can use them.
- Cookies enabled: yes, but the site still logs out usually points to stale site data, a third-party iframe, a mismatched system clock, or an extension stripping cookies.
- Cookie Test passes, Storage Test fails means cookies work, but the app may still break because localStorage or IndexedDB is blocked. Use Fix Local Storage Blocked or Fix IndexedDB Blocked next.
Field note: The review workflow for this guide is intentionally simple: run the Cookie Test, change one browser control, reload, and run it again. That isolates the setting that actually changed cookie behavior instead of stacking several privacy changes at once.
Enable cookies in Chrome
Chrome separates first-party site data from third-party cookie behavior.
- Open
chrome://settings/content/siteData. - Choose Allow sites to save data on your device. Do not use Don't allow sites to save data on your device unless you expect many sites to break.
- Open
chrome://settings/cookies. - If the issue is a normal login or shopping cart on the same site, keep third-party cookies blocked if you prefer; first-party cookies should be enough.
- If the issue is an embedded SSO, payment, or document editor, add the trusted domain under Sites allowed to use third-party cookies. For a whole domain, Chrome accepts a pattern like
[*.]example.com. - Reload the original site and re-run the Cookie Test.
Chrome also lets you temporarily allow third-party cookies for the current site from the address bar when it detects a blocked embedded flow. Treat that as a short diagnostic step, then replace it with a scoped exception if the site is trusted.
Enable cookies in Microsoft Edge
Edge uses similar Chromium storage rules, but the labels are under Edge's cookie permissions.
- Go to Settings > Cookies and site permissions > Manage and delete cookies and site data.
- Turn on Allow sites to save and read cookie data.
- If third-party cookies are blocked, leave the global block on unless the site needs a cross-site embed.
- Under Allow, add the app, identity, payment, or embedded-service domain that should keep cookies.
- If you are testing a broken login, use a normal window first. InPrivate can clear cookies when the session ends.
If Edge is managed by work or school, open edge://policy and check for cookie policies before spending time on local settings.
How to enable cookies in Firefox
To enable cookies in Firefox, start with Standard Enhanced Tracking Protection. This setting allows the first-party cookies used for logins, carts, and preferences while Firefox isolates many cross-site cookies through Total Cookie Protection.
- Open Settings > Privacy & Security.
- Under Enhanced Tracking Protection, choose Standard while testing.
- If you use Custom, make sure you did not choose a cookie option that blocks all cookies or blocks the specific site category your app needs.
- To fix one site, click the shield icon in the address bar and turn protection off for that site, or use Manage Exceptions in Privacy & Security.
- If you changed advanced preferences earlier, check
about:configand make surenetwork.cookie.cookieBehavioris not set to a full block.
For login containers, also confirm you are using the same Firefox profile or container each time. Firefox Multi-Account Containers intentionally isolate cookies by container.
How to enable cookies in Safari on Mac, iPhone, and iPad
To enable cookies in Safari, turn off Block All Cookies for the device you use:
- Safari on Mac: open Safari > Settings > Advanced and deselect Block all cookies.
- iPhone / iPad: open Settings > Apps > Safari > Advanced and turn off Block All Cookies.
- Cross-site flows: open Safari > Settings > Privacy on Mac and check Prevent cross-site tracking only after you know the site works. If an embedded SSO or payment frame fails, test once with cross-site tracking prevention off, finish the flow, then turn it back on.
Safari also removes some third-party cookies and website data when the third-party site has not been visited as a first-party site. If a vendor tells you to "enable cookies," first open the vendor's login domain directly in a normal tab, sign in there, then return to the embedded workflow.
How to disable cookies in a browser without blocking every login
If you want to disable cookies in your browser for privacy, block third-party cookies first. Blocking all cookies also disables many sign-ins, carts, saved preferences, and checkout flows.
- Chrome: open Settings > Privacy and security > Third-party cookies, then choose Block third-party cookies. Use On-device site data only if you need to stop every site from saving first-party data.
- Edge: open Settings > Privacy, search, and services > Cookies, then turn on Block third-party cookies. Turn off Allow sites to save and read cookie data only when you intend to block all cookies.
- Firefox: open Settings > Privacy & Security, select Custom under Enhanced Tracking Protection, check Cookies, and choose which type to block. You can also use Manage Exceptions to block one site.
- Safari: keep Prevent cross-site tracking on to limit cross-site cookies. Use Block All Cookies under Safari's advanced settings only when you accept that many sites will stop working.
After changing the setting, reload the site and run the Cookie Test. A failed result is expected when you block all first-party cookies; with only third-party cookies blocked, the first-party test should still pass.
Clear bad cookies for one site
Do this when cookies are allowed but the site still loops, forgets consent, empties carts, or signs you out after refresh.
- Chrome:
chrome://settings/siteData> search the domain > delete only that site's data. - Edge: Settings > Cookies and site permissions > Manage and delete cookies and site data > See all cookies and site data > delete the affected domain.
- Firefox: Settings > Privacy & Security > Cookies and Site Data > Manage Data > remove the domain.
- Safari on Mac: Safari > Settings > Privacy > Manage Website Data > remove the domain.
- iPhone / iPad: Settings > Apps > Safari > Advanced > Website Data > remove the domain.
Reload, sign in again, and run the Cookie Test. If the site starts working, the old cookie jar was the issue.
Check blockers that override browser settings
Cookie settings can be correct while another layer still strips cookies.
- Privacy extensions: uBlock Origin, Ghostery, Privacy Badger, DuckDuckGo Privacy Essentials, AdGuard, NoScript, and consent-banner blockers can block storage or remove cookie-setting scripts.
- Automatic cleanup tools: Cookie AutoDelete and "clear on close" browser settings can remove the cookie as soon as you leave the page.
- Private mode: Chrome Incognito blocks third-party cookies by default; Firefox, Safari, and Edge private modes can use temporary storage that disappears when the session closes.
- Security software: some endpoint tools inject content filters into the browser. Test a clean browser profile before changing every cookie control.
Run the Browser Privacy Check if the failure appears only in one profile, only on a work device, or only with extensions enabled.
Fix third-party cookie login and checkout issues
You need this section only when a site embeds another domain. Examples include Okta or Auth0 SSO, Google Docs inside a school portal, payment checkout frames, support chat, and embedded BI dashboards.
- Identify the embedded domain from the popup URL, iframe URL, or vendor instructions.
- Add a third-party cookie exception for that embedded domain, not for every site.
- If the browser asks whether embedded content may use saved information, allow it only for a trusted workflow.
- Retry the original action without closing the tab.
- Read Fix Third-Party Cookies Blocked During Login or Checkout if the flow still loops.
For site owners, the long-term fix is usually not asking every user to relax privacy settings. Review the Storage Access API and move authentication to a top-level redirect when possible.
Check time, policy, and profile issues
These are less common, but they explain many stubborn "cookies disabled" messages.
- Clock mismatch: cookies can expire immediately when the device date, time, or timezone is wrong. Use automatic time sync, then clear the site's cookies once.
- Managed policy: open
chrome://policyoredge://policyand look for cookie rules such asBlockThirdPartyCookies,CookiesAllowedForUrls, or session-only cookie lists. - Wrong profile: Chrome profiles, Edge profiles, Firefox containers, and Safari profiles keep separate cookie stores. Sign in and test in the same profile you use for the app.
- Disk pressure: browsers can fail to write site data when the profile or system drive is full. Free space and re-run the Storage Test.
Figure callout: For an IT ticket, capture the Cookie Test result beside the browser's cookie exception list. That single screenshot shows whether the current profile can write cookies and which domains are allowed.
Verify the fix
Finish with a narrow verification loop:
- Run the Cookie Test and confirm cookies are enabled and working in the current tab.
- Run the Storage Test if the site saves drafts, offline data, preferences, or carts.
- Reload the original site and repeat the failing action: sign in, add to cart, accept consent, submit the form, or complete checkout.
- If the test passes but the site still fails, collect the app URL, embedded domain, browser version, extension list, and any
chrome://policyoredge://policyentries before escalating.
