Google Ads access control & privilege security checks
Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.
On Google Ads, Black Cat runs 14 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Google Ads connector needs.
Checks (14)
severity: low Email-Only User Access fix difficulty: easy #
Review Google Ads users with email-only access and remove or upgrade as appropriate
- Navigate to Tools & Settings > Access and security > Users
- Filter users by access level to identify email-only access accounts
- Contact the user or their manager to confirm whether account access is still required
- Upgrade access to an appropriate role if the user needs account access, or remove the user if access is no longer needed
- Document the access review decision
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Excessive Admin Users fix difficulty: medium #
Reduce the number of Google Ads admin users to minimize the blast radius of account compromise
- Navigate to Tools & Settings > Access and security > Users
- Filter users by Admin role
- Review each admin user and confirm whether they require admin access
- Downgrade users who do not require admin access to a more limited role (Standard or Read-only)
- Keep admin access to the minimum number of users required for business operations
- Document the access review decisions
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: low Stale Pending Invitation fix difficulty: easy #
Cancel stale pending Google Ads user invitations that have not been accepted
- Navigate to Tools & Settings > Access and security > Users
- Click the Pending invitations tab to view outstanding invitations
- Identify invitations that have been pending for more than 7 days
- Cancel invitations that are no longer needed or were sent in error
- Re-send invitations if the user still requires access
- Notify the invitee's manager of the cancelled invitation
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Stale User Access fix difficulty: medium #
Remove or deactivate Google Ads users who have not accessed the account recently
- Navigate to Tools & Settings > Access and security > Users
- Review the last sign-in date for each user to identify accounts with no recent activity
- Contact the user or their manager to confirm whether access is still required
- Remove users who no longer need access to the Google Ads account
- For users who still require access, remind them to sign in and confirm their role is appropriate
- Document the access review decision for compliance records
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high Account With No Admin Users fix difficulty: easy #
Assign at least one admin user to each Google Ads account to ensure it can be governed and recovered
- Navigate to Tools & Settings > Access and security > Users
- Confirm that no user holds the Admin role on this account
- Identify the appropriate owner (e.g., marketing manager or agency admin) and invite them with Admin access
- Ensure the invited user accepts the invitation and logs in to confirm access
- Remove any placeholder or service accounts that do not correspond to a real owner
- Document the assigned admin in your SaaS ownership register
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: low Account With Single Admin User fix difficulty: easy #
Add a second admin user to eliminate the single point of failure for account governance
- Navigate to Tools & Settings > Access and security > Users
- Confirm that only one user holds the Admin role
- Identify a backup admin (e.g., a senior colleague or agency contact) and invite them with Admin access
- Ensure the invited user accepts the invitation
- Document both admins in your SaaS ownership register
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: low Stale Standard User Access fix difficulty: easy #
Review Standard-role users whose access was granted more than 180 days ago and confirm it is still required
- Navigate to Tools & Settings > Access and security > Users
- Filter by Standard role and sort by access grant date
- Contact each flagged user or their manager to confirm continued need for access
- Remove users who no longer require access
- Downgrade to Read-only for users who only need visibility without edit permissions
- Document the access review outcome
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.3 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Stale Admin Invitation fix difficulty: easy #
Cancel or re-send admin invitations that have been pending for more than 7 days to reduce the window for account takeover
- Navigate to Tools & Settings > Access and security > Users
- Click the Pending invitations tab
- Identify Admin invitations that have been pending for more than 7 days
- Cancel the invitation if the user no longer requires admin access
- Re-send the invitation if access is still needed and confirm the correct email address was used
- Consider sending to a shared admin inbox to ensure the invitation is not missed
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.2 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Self-Granted User Access fix difficulty: medium #
Investigate and revoke self-granted access to enforce separation of duties for Google Ads account access
- Navigate to Tools & Settings > Access and security > Users
- Identify the user flagged as having granted their own access
- Review the access role granted and the date it was assigned
- Revoke the self-granted access and re-provision it through an authorized approver
- Implement an access request process requiring a second admin to approve new access grants
- Document the remediation and update your access control policy
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.3 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: low Stale Read-Only Invitation fix difficulty: easy #
Cancel or re-send read-only invitations that have been pending for more than 14 days
- Navigate to Tools & Settings > Access and security > Users
- Click the Pending invitations tab
- Identify Read-only invitations that have been pending for more than 14 days
- Cancel the invitation if the user no longer requires access
- Re-send the invitation if access is still needed and confirm the correct email address was used
- Document the outcome in your access request log
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.2 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: low Stale Email-Only User Access fix difficulty: easy #
Review email-only users whose access was granted more than 90 days ago and confirm it is still required
- Navigate to Tools & Settings > Access and security > Users
- Filter by Email-only role and sort by access grant date
- Contact each flagged user or their manager to confirm continued need for email report access
- Remove users who no longer require access
- Upgrade to a higher role if the user needs more than email-only visibility
- Document the access review outcome
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.3 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high Stale Admin Access fix difficulty: easy #
Review admin user access that has not been reviewed in more than 90 days
- Navigate to Tools & Settings > Access and security > Users
- Filter by Admin role and sort by access grant date
- Contact each admin user or their manager to confirm continued need for admin access
- Downgrade to Standard or Read-only role if full admin access is no longer required
- Remove the user entirely if access is no longer needed
- Document the access review outcome
Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium User Access Without Inviter fix difficulty: easy #
Investigate user access records with no recorded inviter to ensure they were properly authorized
- Navigate to Tools & Settings > Access and security > Users
- Locate the user flagged as having no inviter record
- Determine how the access was granted (API, bulk import, or legacy migration)
- Verify the access was authorized through your approval workflow
- If unauthorized, remove the user access immediately
- Document the source of the access grant for audit purposes
Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: low Stale Standard Access Invitation fix difficulty: easy #
Cancel or re-send standard access invitations that have been pending for more than 7 days
- Navigate to Tools & Settings > Access and security > Users
- Click the Pending invitations tab
- Identify Standard role invitations pending for more than 7 days
- Cancel the invitation if the user no longer requires access
- Re-send the invitation if access is still needed and confirm the correct email address
- Document the outcome in your access request log
Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2