Microsoft Advertising Remove User Access | OpsBlu Docs

Microsoft Advertising Remove User Access

How to revoke user access and offboard team members from Microsoft Advertising. Covers account deletion, API key revocation, partial access removal, and.

Overview

Removing user access is a critical security task that should be completed promptly when users no longer require Microsoft Advertising access. Common scenarios include employee termination, contractor completion, role changes, and security incidents.

When to Remove Access

Required Removal Scenarios

Employee Termination:

  • Timing: Same day as termination
  • Priority: High - security risk
  • Process: Coordinate with IT for all system access removal

Contractor End of Engagement:

  • Timing: On contract end date
  • Priority: High
  • Process: Verify contract end date, document removal

Role Change (No Longer Needs Access):

  • Timing: Within 24 hours of role change
  • Priority: Medium
  • Process: Confirm new role doesn't require access

Security Incident:

  • Timing: Immediate (within minutes)
  • Priority: Critical
  • Process: Emergency removal, investigation follows

Remove User from Individual Account

Step 1: Navigate to User Management

  1. Sign in to Microsoft Advertising
  2. Click your account name in top right
  3. Select Accounts & Billing
  4. Click User management in left sidebar

Alternative Path:

  1. Click Tools icon (gear)
  2. Under "Accounts," select User management

Step 2: Locate User

  1. User list displays all active users
  2. Use search box to filter by name or email
  3. Identify user to remove

Step 3: Remove User

  1. Click on user's name or email
  2. User details page opens
  3. Click Remove user button
  4. Confirmation dialog appears
  5. Click Confirm or Remove
  6. User immediately loses access

Step 4: Verify Removal

  1. User no longer appears in User management list
  2. User cannot sign in to account
  3. User's name remains in change history (for audit trail)

Offboarding Checklist

Complete these steps when removing user access:

Before Removal

  • Verify business justification
  • Obtain manager approval
  • Document reason for removal
  • Identify knowledge transfer needs
  • Reassign ownership of:
    • Automated rules
    • Scheduled reports
    • Custom conversion goals

During Removal

  • Remove user from Microsoft Advertising
  • Verify removal successful
  • Remove from Manager Account (if applicable)
  • Cancel pending invitations (if any)
  • Revoke API access/OAuth tokens (if applicable)

After Removal

  • Document removal in access log:
    • Date and time
    • Removed by (admin name)
    • Reason for removal
    • Stakeholder approval
  • Review change history for user's recent actions
  • Monitor account for 24-48 hours
  • Update team contact lists

Emergency Access Removal

For security incidents requiring immediate action:

Immediate Removal Steps

  1. Sign in immediately to Microsoft Advertising
  2. Navigate directly to User management
  3. Locate compromised user
  4. Click Remove - confirm immediately
  5. Verify removal - user disappears from list
  6. Document action: Time, date, reason

Post-Removal Security Actions

  1. Review change history:

    • Filter by removed user
    • Look for suspicious changes in last 24-48 hours
    • Document unauthorized actions
  2. Reset credentials (if user had API access):

    • Revoke OAuth tokens
    • Regenerate developer tokens
  3. Notify stakeholders:

    • Security team
    • Manager/leadership
    • Affected clients (if agency)
  4. Monitor account:

    • Watch for unusual activity in next 7 days
    • Review spend and campaign changes daily

Verify Removal

Confirmation Steps

  1. User list check:

    • Navigate to User management
    • Search for removed user
    • Should return "No users found"
  2. Change history:

    • User's past actions still visible (for audit)
    • User's name appears as "[User Name] (Removed)"
    • No new actions possible

Common Removal Issues & Solutions

Cannot Remove User (Button Greyed Out)

Causes & Solutions:

Cause Solution
Insufficient permissions Only Admin/Super Admin can remove users
User is account owner Transfer ownership first, then remove
Last Super Admin Add another Super Admin first
Session expired Sign out and sign back in

User Still Has Access After Removal

Troubleshooting:

  1. Verify removal completed - Check User management list
  2. User may be cached - Have user sign out and clear cache
  3. User has access via Manager Account - Remove from Manager Account
  4. Multiple Microsoft accounts - Search for alternate email addresses

Removed User by Mistake

Recovery Steps:

  1. Re-add immediately using standard invitation process
  2. User accepts invitation - Access restored
  3. Note: Historical change history preserved

Post-Removal Access Audit

After removing user, verify no access remains:

Microsoft Advertising Access

  • User removed from all individual accounts
  • User removed from Manager Accounts
  • Pending invitations canceled
  • User cannot sign in
  • Google Tag Manager access removed
  • Analytics platform access removed
  • CRM access removed
  • Slack/Teams channels removed
  • Email distribution lists updated

API and Integrations

  • OAuth tokens revoked
  • API access removed
  • Developer token deactivated
  • Third-party tool access removed

Audit Trail

Document removals for compliance:

Required Information:

  • User's full name and email
  • Date and time of removal
  • Removed by (admin name)
  • Reason for removal
  • Approver (if required)
  • Access level being removed

Retention: Maintain access logs for minimum 7 years.

Best Practices

Timing

  • Employee termination: Same day, coordinated with IT
  • Contractor end: On contract end date
  • Role change: Within 24 hours
  • Security incident: Immediate (within minutes)

Documentation

  • Maintain access removal log
  • Document business justification
  • Obtain approvals when required
  • Archive user's campaign documentation

Security

  • Remove all access simultaneously
  • Revoke API and OAuth access
  • Monitor account for 24-48 hours post-removal
  • Review change history for unauthorized actions

Next Steps