How to Secure Ad Account Access: Admin Roles, Partner Access, 2FA, and Offboarding Across Meta, Google, and TikTok

Guides/Agency Accounts

By Ismael Diaby · Published July 31, 2026 · Updated July 31, 2026

bolt

Quick Answer

Secure ad account access by granting each person their own login at the minimum role needed, connecting agencies through partner access rather than shared credentials, enforcing two-factor verification for every user, reviewing access quarterly, and revoking permissions the same day a team member or client relationship ends.

Why ad account access security matters

Every person, partner, and login connected to your ad accounts is a path to your budgets, billing, and customer data. Meta warns that bad actors often target inactive accounts in an effort to gain access to a business portfolio, and Google's security guidance starts from the same premise: anyone with access to your Google Account can access your Google Ads account and look up your advertising data. Meta has also reported that increases in time spent online have come with an increase in cybercrime and fraudulent activity.

The operational risks are concrete:

- **Spend and billing exposure.** Google's best-practices guide tells advertisers to watch for unexpected changes to ads or budgets, and to check bank or credit card statements if they suspect billing information was accessed. - **Compromised credentials.** Practitioner security guidance citing the IBM Cost of a Data Breach Report identifies compromised credentials as the most common initial attack vector — which is why shared logins and orphaned permissions are liabilities, not conveniences. - **Silent drift.** Access granted months ago to a freelancer, a former employee, or a past agency rarely revokes itself. No platform sends you a reminder that a permission has gone stale.

It also helps to separate what can go wrong by layer. A person's login can be phished. An ad account can carry unauthorized users. A Page or dataset can be assigned to the wrong partner. A Business Portfolio — Meta's container for business assets — can be over-provisioned with admins. Each layer has its own controls, and this guide walks through them in order: roles, partner access, login security, offboarding, and monitoring.

Admin roles and permissions

The working principle is least privilege: grant each person the minimum access their job requires, and nothing more. Google's own best practices say to grant the minimum access needed for each user, and its access levels make that practical — Admin users can invite new users and change the account, Standard users cannot, and Read only or Email only access covers people who never need to touch campaigns.

Platform by platform:

- **Google Ads.** Access levels run from Admin down to Read only and Email only. Two structural safeguards matter. First, keep at least two admins: Google warns that if your account has only one administrator, you may lose access to your tags if that user becomes unavailable. Second, consider multi-party approval, which requires a second administrator to approve sensitive actions like adding users, removing users, or changing roles. - **Meta.** People are added to an ad account with roles based on the permissions you want them to have, and assets inside a business portfolio are assigned to people or to partners. Practitioner guidance recommends keeping portfolio admins to two or three people, because a portfolio admin can remove every other admin — over-provisioned portfolios are a known escalation path in account compromises. - **TikTok.** Only Business Center Admins can grant member access to TikTok accounts. Practitioner documentation describes tiered ad account roles (Admin, Operator, Analyst) plus separate finance roles, so campaign staff never need billing permissions by default.

Before sending any invite, do a fifteen-minute mapping exercise: write down each person's name, their job, and the minimum role that job requires. Treat Admin access as needing explicit justification. Revisit the map whenever someone's role changes — permission drift is how a read-only analyst ends up able to edit live campaigns.

Partner and agency access

The structural rule that survives every platform redesign: ownership stays with the business the asset describes, and access flows through partnership. In practice, the client's Business Portfolio owns the ad account, the Page, and the dataset (pixel); the agency's portfolio is added as a partner and receives assigned assets; and the agency assigns its own people internally. Agency staff should never be added as individuals directly on client assets.

Why the model matters:

- **Portability.** If an agency creates the ad account or dataset inside its own portfolio 'for convenience,' the client's spend history and the dataset's learning are trapped when the relationship ends. Practitioner guidance is blunt: get the ownership direction wrong and offboarding means the client loses account history. - **Billing hygiene.** Keep payment methods client-owned unless explicitly agreed otherwise — agency onboarding checklists flag verifying client-owned payment methods as a standard step. - **Revocability.** Partner access is one grant to one business. Ending the relationship is one partner removal, not an archaeology dig through person-level permissions.

Platform mechanics:

- **Meta.** Partners are other Business Portfolios. Meta's developer documentation is explicit that storing customer passwords is not an approved model — access should be granted through the platform, never handed over as credentials. - **Google Ads.** Agencies typically connect through a manager account (MCC). Each Google Account can have direct access to up to 20 Google Ads accounts, so a manager account is the better option at scale. Use the Related managers tab to check whether accounts are linked to managers outside your hierarchy. - **TikTok.** Clients add your Business Center as a partner and choose which ad accounts to share. TikTok allows ad accounts to be linked to multiple Business Centers, so a client can work with more than one partner without transferring ownership.

Two-factor and login security

Two-factor authentication (2FA, or 2-Step Verification) is the highest-leverage login control available: Google's documentation states it can help keep bad actors out even if your password has been compromised.

Enforce it — don't merely suggest it:

- **Meta.** Business portfolio admins can require two-factor authentication for everyone who accesses the portfolio; everyone the requirement applies to must set it up on their personal Facebook account before they can get in. - **Google Ads.** Turn on 2-Step Verification under Access and security, Security tab. If you run a manager account, security mandates let you require 2-Step Verification across all current and future sub-accounts you own, with an effective date you choose. Google also describes its Authenticator app as a more secure verification method than SMS. - **TikTok.** Enable Two-Step Verification for both Ads Manager and Business Center, and enforce it for all members.

Then layer on domain and phishing controls:

- **Allowed email domains.** Google Ads (including at the manager-account level) and TikTok Business Center both let you restrict invitations to approved email domains, so people outside your organization can't be invited in. - **Credential hygiene.** Never share logins between people. Google explicitly advises granting each person access with their own Google Account instead of sharing a username and password, and recommends unique passwords per site. - **Phishing verification.** Google states it will only contact you from an @google.com email domain and will never send an unsolicited message asking for your password. TikTok advises verifying that outreach claiming to be from TikTok for Business is genuine before responding. - **Extra verification for sensitive data.** TikTok's Data Security Verification requires an identity check with a verification code before anyone can access advertising data.

Ready to upgrade your ad account infrastructure?

AdsInfra provides certified agency accounts for Meta, TikTok, and Google. Setup in 2-5 business days.

Talk to a Specialist

Offboarding and revoking access

Offboarding is where access security usually fails, because nothing breaks on day one when you skip it. Practitioner research describes the six-month problem: months after a client relationship ends, many agencies still have access to that client's accounts — not out of malice, but because revocation is invisible and nothing reminds you to do it.

Build a same-day revocation checklist:

- **Google Ads.** Go to Access and security in the Admin menu, find the user, and select Remove access. If an agency manager account is linked, unlink it from the Managers tab. Google's warning is direct: unless you remove inactive users, they can still sign in and make changes. - **Meta.** Remove both layers — the partner connection under Business Settings, Partners, and any individuals added directly under People. Meta's Security Center specifically recommends removing inactive users because bad actors target them. - **TikTok.** Remove members who no longer require access, revoke partner access to ad accounts, and confirm that pending invitations are valid. TikTok's own best practices list removing inactive users as a core hygiene step. - **Your own systems.** Delete stored OAuth tokens and revoke API access — not just the visible platform connection. Practitioner offboarding guidance stresses that a stored token can keep accessing a client's data until it expires, even after the connection appears removed.

Two discipline points:

1. **Don't rely on the other party to remove you.** If you're the departing agency, request written confirmation; if you're the account owner, verify each removal yourself in the platform's access settings. 2. **Document every revocation** — date, platform, who performed it, and a screenshot or confirmation email. Meta does not document a guaranteed timeline for every access change to propagate, so treat a removal as complete only after you verify it in Business Settings.

Monitoring for unauthorized changes

Access security is not a one-time setup; it is a recurring audit. The cadence that platform and practitioner guidance converges on:

- **Regular account checks.** Google advises signing in regularly to look for unexpected or unauthorized activity such as changes to your ads or budget, and checking bank or card statements if you suspect billing information was accessed. - **Monthly security dashboards.** Google Ads' Security Agent monitors login activity, flags users behaving outside their normal patterns, and surfaces security debt — unused accounts and over-permissioned users — as suggestions in the Security tab. Google recommends reviewing those suggestions at least once a month. Meta's Security Center similarly lists recommended actions, such as removing inactive users, for anyone with full control of the portfolio, and lets you track progress. - **Quarterly access reviews.** Practitioner checklists recommend a full review every 90 days: Is each client still active? Does each person still need access? Are permission levels still appropriate? TikTok's own guidance likewise says to periodically review and update user roles and permissions in Business Center. - **Approval-based change control.** On Google Ads, multi-party approval routes sensitive changes — adding users, removing users, changing roles — to other administrators for approval. Requests expire after 20 days if nobody acts, and approvals arrive as in-product notifications rather than email, so checking notifications is part of monitoring, not optional. - **Audit trails.** Agencies should log who accessed which client account, when, and why. When a client calls about an unauthorized campaign change, an audit log turns a guessing game into a lookup.

Every quarter, reconcile people and partners against reality: every person on the account should match a current team member, and every partner connection should match an active engagement. Practitioner audits consistently surface the same two findings — former employees with admin access and former clients still partnered. Both are one click to fix, and both are real risks while they persist.

Frequently Asked Questions

How often should I audit who has access to my ad accounts?expand_more
Platform and practitioner guidance points to a layered cadence: sign in regularly to check for unexpected changes to ads or budgets, review security dashboards (such as Google Ads' Security Agent suggestions or Meta's Security Center) at least monthly, and run a full access review — people, roles, and partner connections — every quarter. Revoke access the same day anyone leaves.
Should my agency own my ad account, or should I?expand_more
You should. The durable model is that the business the asset describes owns the ad account, Page, and dataset, and the agency receives partner access. If the agency owns the assets, you risk losing spend history and pixel learning when the relationship ends, and offboarding becomes a negotiation instead of a revocation.
Is it safe for my team to share one login to an ad account?expand_more
No. Google explicitly recommends granting each person access with their own Google Account rather than sharing a username and password, and Meta's developer documentation says storing customer passwords is not an approved model. Shared logins destroy per-person accountability and turn one phished device into a full account compromise.
What is the difference between partner access and adding someone as a person?expand_more
Adding a person grants an individual access to specific assets. Partner access is a business-to-business grant: the client assigns assets to the agency's Business Portfolio (or the agency links via a manager account), and the agency assigns its own staff internally. Partner access keeps staffing changes inside the agency and makes offboarding a single removal.
Does two-factor authentication guarantee my ad account can't be compromised?expand_more
No control is a guarantee. Two-factor verification adds a second layer of defense — Google's documentation says it can help keep bad actors out even if your password has been compromised — but it works best combined with least-privilege roles, domain restrictions, regular access reviews, and prompt offboarding.
What should I do immediately if I suspect unauthorized access?expand_more
Google's guidance for a suspected compromise: run a malware scan on devices used to access the account, change the password (and any account reusing it), and enable two-step verification. Then review the user list and recent account changes, remove anything you don't recognize, and report the activity to the platform.
shield_with_heartAdsInfra

Scaling past $50k/mo?

AdsInfra coordinates agency ad-account access, billing, permissions, and restriction-response workflows for high-spend teams across Meta, TikTok, and Google.

  • check_circleCoordinated account access and billing workflows
  • check_circleHuman-led restriction review and escalation
  • check_circlePlatform-specific onboarding and compliance checks