About multi-party approval for Google Ads

Multi-party approval (MPA) is a security feature for Google Ads designed to protect your account from unauthorised activity by requiring a second account administrator to verify sensitive changes. Sensitive actions like adding users or changing user roles will prompt other administrators of your account to approve these changes.

This article explains how multi-party approval works and how to manage multi-party approval requests in your account.

Prefer video learning? Watch the 60 second summary.

For subtitles in your language, turn on YouTube captions. Select the Settings icon Image of YouTube settings icon at the bottom of the video player, then select Subtitles/CC and choose your language.


On this page


Get started with multi-party approval

Multi-party approval secures your account by requiring another administrator's approval for different Google Ads workflows. This can help to block hijacking attempts and unauthorised actions from occurring on your account.

Sensitive actions like adding a new user, removing an existing user or changing user roles will require approval from a second administrator to complete. As security needs evolve, additional actions may also require this approval process.

Note: Read-only roles and API users are exempt from this approval process.

About the approval process

When you make a sensitive change to a Google Ads account, a request is sent to all administrators within the hierarchy for approval. All eligible account administrators within your hierarchy will receive an in-product notification to review these changes.

Direct administrators and owner managers of the requestor receive individual notifications for each request, while others in the hierarchy receive a combined digest for multiple requests. Since emails aren’t sent for these approvals, it's important to check your in-product notifications regularly.

Account administrators have 20 days to approve or reject a request before it expires. Requests automatically expire if they aren’t acted upon within 20 days. If the action is still necessary, restart the process to generate a new approval request.

Important: If your other account administrators aren’t responding to a request, Google Ads support can’t approve or deny the request for you. To maintain the security of your account, contact your internal account administrators directly to complete the approval.

There are currently 3 request statuses for multi-party approval. These statuses will show next to any actions taken in the account:

  • Complete: The action was reviewed and approved by an administrator. The action takes effect and the initiator is notified.
  • Denied: The action was reviewed and rejected by an administrator. The proposed action is blocked.
  • Expired: If no action is taken within 20 days, the action is rejected.

Who can complete approvals

Multi-party approval requests can be completed by any user with Admin access to the account. If your account requires multi-party approval for sensitive changes, change requests can be approved at the individual account level as well as by any linked manager accounts.

Multi-party approval is only applicable for accounts with more than 3 administrators. If your account transitions from having multiple admin users to a single admin, multi-party approval is paused for your account and all pending requests are cancelled to help protect your account. After you add additional admins to your account, you’ll automatically be re-enrolled. The only exception is after a compromised event, where any pending legitimate requests are automatically approved after removing any unauthorised activity.


Linking existing child accounts to a manager account

When a manager account (MCC) submits a request to link an existing, independent Google Ads account as a child account, Multi-party approval (MPA) is enforced to safeguard both accounts.

What it is

This scenario occurs when a manager account attempts to connect with a Google Ads account that was created independently and is not currently within the manager account's hierarchy.

  • Location in Google Ads: In the parent manager account, this request is initiated by navigating to Accounts > Sub-account settings >Link an existing account and add the external account CIDs 
  • Multi-party approval status: Enforced (requires secondary administrator approval).

Managing requests with the 'Multi-party approvals' tab

To streamline account management, the Access and security section includes a dedicated Security requests tab. This tab categorises pending approvals, allowing administrators to find, review and act on requests efficiently.

What it is

The 'Security requests' tab organises pending multi-party approval (MPA) requests by category (such as User management, MCC account linking or Billing changes). Instead of sifting through an unsorted list, approvers can quickly identify high-priority requests and review them individually. Where to find it: Sign in to your Google Ads account, navigate to Admin > Access and security and select the Security requests tab.

Key features and how to use them

1. Filter and view requests by category

  • Each category displays a summary card showing the total number of pending items awaiting review.
  • Click View next to a category to open a focused table showing all requests under that specific category.

Note on revoking requests:

  • Revoke is reserved strictly for requests you initiated that have not yet been approved or denied.
  • When reviewing or selecting MPA requests created by other administrators, the checkbox options for 'Revoke' are disabled, and you will only have the option to Approve or Deny.

You can review change requests on the 'Access and security' page in your Google Ads account. Notifications for pending requests appear at the individual account level and in any linked manager accounts. Manager accounts can view and approve pending requests for any of their linked child accounts.

To streamline account management, the Access and security page in Google Ads includes a dedicated Security requests tab. This tab categorises pending approvals, which allows administrators to find, review and act on requests efficiently. This tab organises MPA requests by category, such as user management, manager account linking or billing changes, so approvers can quickly identify and review high-priority requests.

Approve or reject a request

After a request is submitted, another administrator must review and accept the request for it to take effect. Here’s how to review your pending requests:

  1. Go to Access and security in the Admin menu Admin icon.
  2. In the 'Pending invitations' menu, select Review request.
  3. Review the details of each request. Select Approve to approve the request or Deny to reject it. You can manage added users in the 'Users' tab under Access and security.

Revoke a request

When reviewing or selecting MPA requests created by other administrators, the checkbox options for 'Revoke' are disabled, and you will only have the option to 'Approve' or 'Deny'.

If you need to revoke a pending request that you initiated, follow the steps below.

Note that you can only revoke a request if it hasn’t already been approved or denied by another administrator.

  1. Go to Access and security in the Admin menu Admin icon .
  2. In the 'Pending invitations' menu, select Revoke request next to a request that you’d like to cancel.

This will delete the notifications associated with the request for all other account administrators.


Multi-party approval email notifications and reminders

To help you manage Google Ads workflows efficiently and stay informed about important account actions, Google Ads sends automated email notifications for multi-party approval (MPA) requests. 

What it is

Email notifications and reminders keep account administrators up to date on pending Google Ads workflows (like account linking updates or user access changes). These emails help ensure that approval requests are reviewed promptly before they expire. 

Email types and who receives them

Email type

Purpose

Who receives it

Approval request

Notifies administrators that a Google Ads workflow was initiated and requires secondary approval.

All eligible Google Ads account administrators in the hierarchy.

Request approved

Confirms that a pending request has been reviewed and accepted.

The administrator who originally submitted (initiated) the request.

Request rejected

Confirms that a pending request was reviewed and denied.

The administrator who originally submitted (initiated) the request.

Pending reminder

Send one reminder email if the MPA is not approved after 3 days.

All eligible Google Ads account administrators in the hierarchy with pending actions.

Note: Emails are sent directly to the email addresses associated with your Google Ads admin logins. Suspended accounts will not receive these email notifications.

What action should you take?

If you receive an approval request or reminder:

  1. Review the details: Open your email to check the requested action and who initiated it.
  2. Access your account: Click the link in the email or sign in to Google Ads and navigate to Admin > Access and security.
  3. Approve or Deny: Locate the request under Pending invitations and select Approve or Deny.

If you receive an approved or rejected notification:

  • Approved: No further action is required. The proposed change has taken effect immediately.
  • Rejected: The proposed change was blocked. Contact your fellow account administrators directly if you need to discuss the request or resubmit it.

Additional recommendations and best practices

  • Check in-product notifications: While email reminders are sent every 6 hours for pending actions, you can also review and act on pending requests at any time via the notifications bar inside Google Ads.
  • Act before the 20-day expiry: Requests automatically expire and are rejected if no action is taken within 20 days. If a request expires, you will need to restart the change process from the beginning.
  • Maintain updated admin lists: Ensure that all listed account administrators have active, monitored email addresses so critical approval requests are not missed.
  • Support cannot override approvals: To maintain strict account security, Google Ads Support cannot approve, deny or bypass MPA requests on your behalf. Always coordinate directly with your internal team members.

Was this helpful?

How can we improve it?
Search
Clear search
Close search
Main menu
5100338545023808360
true
Search Help Centre
true
true
true
true
true
true
73067
false
false
true
true
false
false