
Google Ads is testing a new security feature to disallow free domain email addresses (such as @gmail.com or @yahoo.com) from performing sensitive actions on a Google Ads advertiser account. Google will only allow those using corporate emails to perform such actions.
Again, this is a limited test right now, Google said it is "currently being piloted for a subset of advertisers." "You will receive an email notification if your account is enrolled in this updated security requirement," Google added to this new help document.
Google said this is to "enhance account security and minimize the impact of unauthorized access."
I guess this comes in the wake of the wave of Google Ads account hijacks.
What are "sensitive actions," Google said "The list of sensitive actions above are non-exhaustive and are subject to change without prior notice." But Google listed a couple of examples including account linking updates and user access changes.
Here are some FAQs on this policy pilot change:
Will adding a new corporate email user trigger Multi-Party Approval (MPA)? Yes, if your Google Ads account currently has 3 or more active administrators, inviting a new user or modifying administrator privileges will trigger Multi-Party Approval (MPA). Another existing administrator on the account will need to approve the request before the new corporate email user can be added.
Will I need to set up a new passkey for my corporate email account, or can I use my old one? You will need to set up a new passkey. Passkeys are specific to each individual Google Account/email address. Because your new corporate email account is distinct from your previous free domain account, you must create and associate a new passkey specifically for your corporate login credentials.
Can users with free domain emails still view or manage basic campaigns? Users with free domain emails (@gmail.com) can continue to view reports and make routine campaign edits depending on their access level, but they will be restricted from completing sensitive actions.
What happens if I try to perform a sensitive action with a free domain email after the policy takes effect? If you attempt a sensitive action while signed in with a free domain email, you will receive an in-app prompt instructing you to switch to an authorized corporate email domain before completing the action.
Forum discussion at X.

