Google Ads Account Access Security in 2026: Passkeys, Corporate Email, Approvals
A familiar 2026 scene: a client sends a manager account link invitation, the specialist opens it to accept — and hits a prompt asking to confirm the action with a passkey they do not have, from a personal email address that no longer qualifies for that action. Launch slips a week. Nothing malfunctioned. Google Ads account access security was rebuilt along three lines this year: mandatory passkeys for sensitive actions, restrictions on free email domains, and multi-party approval in accounts with several administrators. Here is what changed, what breaks in real teams, and how to restructure access before it becomes a Friday-evening emergency.
What counts as a “sensitive action”
The term sounds vague; the list is specific, and it maps precisely onto how accounts get stolen.
- Account linking updates: accepting or rejecting a manager account invitation, unlinking an account from a manager.
- User access changes: granting account access, modifying a user’s role, cancelling pending invitations.
Google states explicitly that the list is non-exhaustive and may change without prior notice. The working assumption should therefore be that anything altering who owns and who controls the account will eventually require step-up verification.
Note what is absent: campaign edits, bids, budgets, and creative are not on the list. Day-to-day buying is unchanged. What changed is rights management.
Three 2026 changes in one table
| Change | When | Who it affects | Status |
|---|---|---|---|
| Passkey required for sensitive actions | From July 15, 2026; notifications sent from May 8 | Anyone handling links and access changes | In force |
| Free email domains blocked from sensitive actions | No published effective date | Accounts enrolled in the pilot; notified by email | Piloted with a subset of advertisers |
| Multi-party approval (a second admin confirms) | As it rolls out | Accounts with several active administrators | Rolling out |
The first is already mandatory, the second can arrive by email at any moment, the third switches on as your admin count grows. Preparing for all three at once is cheap; losing administrative control mid-season is not.
Passkeys: how not to lose two days
A passkey is password-free confirmation: a cryptographic key stored on your device and unlocked with biometrics or a PIN. It cannot be forwarded in chat, dictated over the phone, stored in a shared password manager, or handed to someone impersonating support. That is the entire point.
Setup sequence
- Pick a device that genuinely stays with the person — a work phone or laptop, not the shared tablet in the office.
- Create the passkey in the security settings of the Google Account you use to sign into Google Ads.
- Budget time for pairing: Google describes it as one to two days, and troubleshooting guidance suggests waiting a full 48 hours.
- Test it on a harmless sensitive action — granting access to a test user — rather than during a live client handover.
- Register a backup: a second key on another device, so a lost phone does not mean lost control of the account.
Where people get stuck
| Situation | What happens | Fix |
|---|---|---|
| Shared team login | A passkey cannot be shared — only the device owner can confirm | Individual accounts with roles instead of a shared login |
| Autogenerated passkey on Android | Cannot be used to verify sensitive actions in Google Ads | Create the key manually and test it |
| Corporate SSO | SSO does not waive the requirement — a passkey is still needed | Distribute keys in advance to everyone doing admin work |
| The action is needed right now | Key created an hour ago has not synchronised yet | Create keys before you need them, not during an emergency |
Corporate email instead of free mailboxes
In parallel, Google is piloting a restriction where signing in from a free domain — @gmail.com, @yahoo.com and similar — blocks sensitive actions. Report viewing and routine campaign edits remain available within the granted role, so the specialist keeps working but cannot accept a link or grant access.
The detail that defuses most of the panic: you do not need to buy a paid productivity suite. Registering a Google Account on an address at your existing business domain satisfies the requirement at no additional cost.
Who this hits hardest
- Freelancers and small agencies who have run client accounts from personal Gmail for years.
- Teams where one person performs all administrative operations from a legacy personal account.
- Projects where access was granted quickly to a contractor’s address and never revisited.
A manager account owner can pre-emptively require specific email domains on sub-accounts. Doing that proactively beats discovering the rule after half the team loses admin rights.
Multi-party approval: when one admin is not enough
The third layer requires a second administrator to confirm a sensitive action. The reasoning is straightforward: even a fully compromised account cannot transfer control single-handed.
One caveat worth knowing up front: Google’s documentation contradicts itself on the threshold. One page says “three or more active administrators”, another says “more than three administrators”. An account with exactly three sits inside one rule and outside the other. Plan for the stricter reading — assume three admins already means approvals are on.
| Parameter | Value | What to account for |
|---|---|---|
| Trigger threshold | 3 administrators (strict reading) | Count every active admin, including contractors and forgotten accounts |
| Approval window | 20 days | After that the request expires and the process restarts from scratch |
| Exemptions | Read-only access and API access | Analysts who only read data are unaffected |
Twenty days looks generous right up until holiday season. The realistic failure: the request goes to your only second administrator, who is away for three weeks, the window expires, and you start again. Hence the rule — at least two reachable administrators at any time, ideally in different time zones if the team is distributed.
Why the platform is tightening this specific screw
All three changes target the same attack: account takeover. The pattern rarely varies. An attacker gets into an employee’s mailbox or session, leaves campaigns untouched, and quietly adds themselves as an administrator or relinks the account to their own manager account. From that point they control the budget, the billing profile, and the account’s history, and the rightful owner finds out from the charges.
The defence follows from the attack. Passwords can be phished, one-time codes can be talked out of people by someone posing as support, but a passkey physically cannot be handed over — it never leaves the device. The corporate domain requirement adds a second barrier: mail on your domain is controlled by your organisation, not by the individual, so it can be centrally disabled on offboarding or during an incident. Multi-party approval closes the remaining gap: full control of one account is no longer enough to change ownership structure.
Programmatic access is moving the same way — in August 2026 the platform began piloting account takeover prevention measures at the API level. The direction is clear and unlikely to reverse: administrative operations are migrating out of “username and password” territory into verified identities and devices. Build processes on that assumption rather than on hopes of a rollback.
Google Ads account access security: restructuring roles in a team
| Role | Who | Can do | Passkey and corporate email |
|---|---|---|---|
| Admin | 1–2 people in-house | Links, access grants, billing | Required |
| Standard | Buyers running campaigns | Campaigns, bids, creative, conversions | Recommended |
| Read-only | Analysts, clients, executives | Reports and exports | Not required |
| Email-only | External report recipients | Scheduled reports | Not required |
- No shared logins. One person, one account. A shared login is no longer just a risk — it is a hard technical block, because the passkey lives on one specific person’s device.
- Minimum admin rights. A buyer does not need admin access for daily work. Fewer admins means multi-party approval triggers later and the attack surface stays smaller.
- Quarterly review. Departed employees, former contractors, test accounts — this accumulates for years. Make access review part of the regular Google Ads account audit rather than an occasional impulse.
Handover deserves its own procedure. When a specialist leaves you revoke their access — but if they were the only holder of a working passkey for sensitive actions, the ability to manage links leaves with them. Delegation practices that avoid this are covered in hiring and delegating media buying.
A 15-minute checklist for today
- How many admins you actually have. Open the user list in every account and count administrative roles. There are almost always more than you remember.
- Which domains their emails sit on. Any admin on a free domain is a potential point of failure.
- Whether a second admin is genuinely available. Not listed — available: responsive, holds a device with a key, not away for three weeks.
- Whether the people who handle links have working passkeys. Confirmed by a test action, not by “I think I set that up”.
- Who owns the billing profile. Often it is a former contractor’s account or a founder’s personal address nobody can access.
- Whether backup keys exist. A second device per admin is cheap insurance against a broken phone.
- Who receives platform emails. Pilot notices go to the account owner’s address; if that inbox is abandoned, you learn about changes last.
Reporting access deserves a separate line. Broad permissions are often granted simply because someone wants numbers. Read-only access or a scheduled export solves that — see media buyer dashboards and reporting for a setup where nobody needs to log in for a single metric.
A two-week transition plan
| Days | Actions | Outcome |
|---|---|---|
| 1–2 | Inventory: export every user in every account, note roles and email domains | A table of who, where, which email, which role |
| 3–4 | Create corporate addresses for everyone performing admin actions | No administrator on a free domain |
| 5–7 | Create passkeys, wait for synchronisation, verify with a test action | Confirmed working keys for all admins |
| 8–10 | Rebuild roles: strip excess admin rights, delete stale accounts | Two admins, everyone else standard or read-only |
| 11–14 | Write the runbook: who approves, what happens during holidays, escalation path | A one-page document the whole team can find |
Agencies with dozens of client accounts
- Keep admin rights at the manager account level. Inside client accounts, staff should hold standard access, not admin.
- Two on-duty admins minimum. One on holiday, the other approves — ideally in different time zones.
- Corporate addresses for the whole team, not just admins. The pilot is expanding, and retrofitting is always more painful.
- Client onboarding clause. Put it in the kickoff checklist: the client must have an administrator with a working passkey and a business email, or the link cannot be accepted on schedule.
- Bulk tooling. Routing edits through Google Ads Editor and bulk operations reduces how many people need broad permissions in the first place.
If the access structure itself has become the bottleneck, managed agency accounts from PPC Rebels come with the manager structure already in place — details on the agency account rental page.
How access connects to money and data
- Billing. The payment profile is tied to specific people. Losing access to it stops delivery at the first failed charge, no matter how well the campaigns are built.
- Conversions and links. Unlinking from a manager account or losing access to linked analytics products breaks conversion flow. Bid strategies do not fail loudly — they simply start optimising on incomplete data.
- Account history. An account with accumulated spend and outcome history is an asset. Losing it means downtime plus a return to new-advertiser status, with the volume constraints described in limited ad serving in Google Ads.
Explaining the change to a client
A specific agency headache: telling a client why “just give me access” now takes more than five minutes. The framing that works better than arguing: this is not agency bureaucracy but a change in the advertising platform’s own rules, aimed at account takeover, and it protects the client’s money first.
Practically, put three things in the kickoff email — exactly which access level is needed and why, that the client needs an administrator with a business email and a configured passkey on their side, and how long preparation takes. One paragraph at the start of a project saves a week of back-and-forth at the moment the budget is signed and everyone is waiting on launch.
Six expensive mistakes
| Mistake | How it ends |
|---|---|
| Creating a passkey at the moment you need it | Up to 48 hours of waiting and a missed launch |
| A single administrator on the account | Holiday, illness, or a lost phone paralyses management |
| Working from personal email “because we always have” | Sudden loss of admin capability when the pilot reaches you |
| Shared department login | The key belongs to one device, so only one person can ever confirm |
| Not revoking departed users | Admin count grows, approvals trigger sooner, exposure widens |
| Ignoring platform emails | Pilots and changes are announced by email; a missed notice becomes a surprise |
If access is lost or the account is compromised
- Change the Google Account password and sign out of all active sessions on every device.
- Review registered passkeys and remove unknown ones, then review the Google Ads user list and revoke unnecessary access.
- Check the billing profile: payment methods, details, limit changes.
- Read the change history for the suspicious period: new campaigns, changed final URLs, new users.
- Check manager account links for anything you did not authorise.
- Document everything with screenshots and timestamps before contacting support.
Check measurement separately: swapped tracking templates or disabled conversion actions are a common side effect that teams later blame on “the algorithm” for weeks. Verifying the chain is covered in first-party data and Data Manager, and consent handling in Consent Mode v2 and ad privacy.
FAQ
Which actions specifically are “sensitive”?
Account linking updates (accepting, rejecting, and unlinking from a manager account) and user access changes (granting access, changing roles, cancelling invitations). Google states the list is non-exhaustive.
When did the passkey requirement start?
July 15, 2026, with notifications sent from May 8, 2026.
Can an authenticator app be used instead?
Alternatives such as one-time code apps are framed as transitional fallbacks rather than equivalent replacements. Plan for passkeys.
Does corporate SSO exempt us?
No. Single sign-on does not waive the requirement — sensitive actions still need a passkey. Build that into your IT policy in advance.
Why is my passkey rejected?
A common cause is an autogenerated passkey on Android, which cannot verify sensitive actions in Google Ads. Create one manually and test it.
Do I need a paid workspace subscription for business email?
No. Registering a Google Account on an address at your own domain is enough; no separate paid subscription is required for this.
What still works from a personal address?
Viewing reports and making routine campaign edits within the granted role. The restriction targets administrative operations.
At how many admins does multi-party approval start?
The documentation conflicts — “three or more” in one place, “more than three” in another. Plan for the strict reading: three administrators.
What if the second admin never approves?
The request is valid for 20 days, then expires and must be restarted. That is why at least one reachable backup administrator is essential.
Does API access need approvals?
API access and the read-only role are exempt from multi-party approval.
How does this affect handing an account to a new agency?
It lengthens the timeline: the incoming administrator needs a business email and a configured passkey, and pairing can take up to two days. Build that into the transition plan.
If I only have time for three things?
Appoint two administrators on corporate addresses, create and test their passkeys, and strip excess admin rights from everyone else. That alone prevents the worst-timed outage.