Setting a Custom Access Denied (403) and Page Not Found (404) Page

What these pages are

When a visitor lands on a page they can't see or that doesn't exist, your site shows an error page. By default, these are plain, generic messages. You can replace them with pages you create yourself, so visitors get a clear explanation and a way forward instead of a dead end.

  • 403 (Access Denied): The page exists, but the visitor is not allowed to view it. This usually happens with unpublished or restricted content, or a section that requires login.
  • 404 (Not Found): The page doesn't exist at that address. This usually happens with an outdated link, a mistyped URL, or content that was removed or moved.

Why customize them

  • Visitors stay on your site instead of leaving.
  • You can point people to the right place, such as your home page, search, or a contact.
  • The messaging matches your site's voice and the Harvard design standards.

Before you begin

You'll need Site Administrator permissions to edit Basic Site Settings. If you don't see the settings screen described below, ask your Portfolio Manager or contact HWP through ServiceNow.

Step 1: Create the page

Create each error page as you would any other basic page on your site.

  1. Add a new page and give it a clear title, such as "Page Not Found" or "Access Denied."
  2. Write the content (see the suggestions below).
  3. Publish the page. An unpublished page cannot be shown to visitors, so the custom error page will not appear.
  4. Note the page's URL path (for example, /page-not-found). If you haven't set a URL alias, the path will look like /node/123. You'll need this in Step 2.

You need to create two separate pages, one for 403 and one for 404. You can also set up only one of them.

What to include on the page

For a 404 page:

  • A plain statement that the page couldn't be found.
  • A link to your home page.
  • A link to your site search or main sections.
  • A way to report a broken link or get help.

For a 403 page:

  • A plain statement that the visitor doesn't have access to this page.
  • A short explanation of why this might be (for example, "This page may be restricted or no longer available").
  • A link to your home page.
  • Contact information, if visitors might need to request access.

Write in plain language and avoid technical terms such as "403" or "404" in the page body. Don't include sensitive details about what the restricted content is or why access is limited.

Step 2: Assign the pages in Basic Site Settings

  1. Go to Site Settings > Basic Site Settings.
  2. Find the field labeled 403 (access denied) page and enter the path of your access denied page.
  3. Find the field labeled 404 (not found) page and enter the path of your page not found page.
  4. Click Save configuration.

Enter only the path that follows your site's domain, beginning with a slash (for example, /page-not-found), not the full web address.

Step 3: Test it

  1. Open a private or incognito browser window, so you're viewing the site as a visitor and not as a logged-in editor.
  2. To test the 404 page, add something nonsensical to the end of your site's address (for example, yoursite.harvard.edu/this-page-does-not-exist).
  3. To test the 403 page, visit the address of an unpublished or restricted page.
  4. Confirm your custom page appears and its links work.

The address in the browser will stay the same as the one the visitor tried to reach. Only the content displayed changes.

Tips and things to watch for

  • Keep both pages published and publicly viewable. If a visitor can't view the error page itself, they'll see the default message instead.
  • Don't delete or unpublish the pages without updating the settings. If you remove a page that is assigned here, visitors will fall back to the default message.
  • Check your links periodically. If your home page or key sections change address, update the links on your error pages.
  • Keep it simple. An error page is a helpful pointer, not a place for long content or announcements.
  • Don't link the error pages from your menus. They are meant to appear only when something goes wrong.
See also: