Meta Business Portfolio Security Checklist for Ecommerce Teams
A practical security checklist for Meta business portfolios covering access, permissions, connected assets, monitoring, and offboarding.
A Meta business portfolio (formerly Business Manager) can contain Pages, ad accounts, Instagram accounts, datasets, catalogs, apps, and financial permissions. Access is not all-or-nothing: Meta distinguishes full control, partial access, asset permissions, and finance access in its current permissions model.
Key takeaways
- Require a passkey or two-factor authentication for every person with access.
- Give full control only to people who need it; use partial access and asset-specific tasks elsewhere.
- Review people, partners, apps, system users, payment settings, and Business history on a schedule.
- Preserve evidence before changing suspicious campaigns or access.
Access hygiene
1. Require stronger authentication for every user. In Meta Business Suite Settings, open Security Center and require two-factor authentication where the control is available. Meta's security recommendations advise removing people who have neither a passkey nor two-factor authentication. One unprotected user can weaken the portfolio's security.
2. Remove inactive and former users. Review access at least quarterly and during every offboarding. Meta specifically recommends removing people who have not logged in to the portfolio within 90 days, especially those with full control.
3. Limit full control. Meta recommends granting full control only to people who need it, ideally ten or fewer. Its permissions guidance explains that full control can manage settings, people, tools, and business assets. For a small ecommerce team, keeping two active, well-secured people with full control can be a sensible internal policy, but “two or three” is not a universal Meta rule.
4. Use partial access and asset-specific permissions. Assign only the Pages, ad accounts, catalogs, datasets, or tasks required for the person's job. Do not rely on the former Advertiser/Analyst hierarchy; Meta now describes full control, partial access, and task-based permissions.
5. Use named accounts. Do not share one login among employees or contractors. Named access supports individual authentication, attribution, and offboarding.
Partners, apps, and assets
6. Review partner access. Match every partner to an active business relationship and specific assets. Meta supports giving an agency partner access to selected business assets, with either full control of an asset or partial access for specified tasks. Use the narrowest permissions that support the work.
7. Review apps, integrations, and system users. Identify who owns each integration, what assets and permissions it uses, and whether it is still required. Revoke unauthorized or abandoned access. Tokens vary in scope and lifetime, so document rather than assume what a password change will invalidate.
8. Verify domains where relevant. Meta's domain-verification control confirms domain ownership in Meta Business Suite and supports control over link-editing permissions. It is not a general guarantee against impersonation, and setup time depends on the verification method and DNS access.
9. Maintain resilient ownership. Keep at least two active, trusted people with full control so loss of one account does not strand the business. Protect both with passkeys or two-factor authentication, and do not use a dormant “backup” account that nobody maintains.
10. Review dataset, pixel, catalog, and finance permissions. Access is permission-specific. Confirm who can view or manage each asset and who has finance access to transactions, invoices, account spend, or payment methods. Remove permissions that are no longer needed.
Billing controls
11. Set documented spending controls. Review campaign budgets and any available account spending limit. Meta describes an ad account spending limit as a limit across campaigns that can reset manually or automatically. Availability and behavior can vary, and an authorized user may be able to change settings, so do not treat it as a hard security boundary.
12. Separate advertising payment methods where practical. A dedicated card can simplify reconciliation and issuer controls, but card limits, pending authorizations, and replacement effects are determined by the issuer. Document who can change payment methods and who receives issuer alerts.
Detection and incident readiness
13. Review Business history. Check Business history in Meta Business Suite Settings for important portfolio events and access changes. Do not assume it records every action. Meta allows people with full control to download people permissions and business history, which can support a periodic review.
14. Configure Meta and payment notifications where available. Review notification settings for each responsible person and verify that security and billing messages reach a monitored address. Available alert types differ by account and role; notification settings are not a substitute for access reviews.
15. Baseline spend and approved destinations. Keep a per-account record of expected spend ranges and domains used in active ads. A deviation is a reason to investigate, not proof of fraud. Our guide to ad spend alerts on Meta, Google, and TikTok explains practical thresholds.
16. Write and test an incident plan. Put evidence capture first:
- screenshot unfamiliar campaigns, ads, transactions, and Business history;
- pause unfamiliar campaigns and ads without deleting them;
- end active sessions and secure affected personal profiles;
- remove unauthorized people, partners, apps, system users, and asset permissions;
- review Billing & payments and payment methods;
- scan affected devices and browsers for malware; and
- contact Meta Support and preserve the case number.
Meta's compromised-business guidance lists unauthorized access, unrecognized campaigns, and unexpected spend as warning signs. If you find one, start with AdFence's Facebook Ads emergency recovery guide, then follow the full Facebook ad account recovery guide.
Why two-factor authentication is not the only control
Two-factor authentication reduces password-only compromise risk, but it does not prevent every form of session theft. Meta's technical analysis of NodeStealer found malware targeting Facebook session cookies and saved Facebook, Gmail, and Outlook credentials. WithSecure's primary Ducktail research describes malware targeting people with Facebook Business access and abusing authenticated sessions.
Reduce exposure by keeping systems and browsers updated, removing untrusted extensions and software, treating unexpected archives and executables as suspicious, and using a dedicated browser profile for business administration where practical. If malware is suspected, stop using the device for administration until it has been assessed and cleaned.
Agency access and offboarding
Use Partner access where available rather than sharing credentials or adding an agency worker as an internal owner. Grant only the assets and tasks required. On the contract end date:
- remove or reduce the partner's access;
- check for people, apps, system users, or integrations added during the engagement;
- review finance access and payment methods;
- confirm dataset, pixel, catalog, Page, Instagram, and ad-account permissions; and
- record the review owner and date.
Recommended review cadence
- Weekly: spend against baseline and destination domains in active ads.
- Monthly: Business history, user list, and notification delivery.
- Quarterly: people, partners, apps, system users, asset permissions, finance access, and payment settings.
- After every personnel or vendor change: immediate offboarding and permission review.
- Twice yearly: retest two-factor or passkey coverage, ownership resilience, domain verification, and the incident plan.
These are operational recommendations, not Meta-mandated intervals. Increase the cadence for high-spend accounts or during major campaigns.
Keep reading
More practical notes for protecting your ad operations.
Why Are My Facebook Ads So Expensive? 12 Causes to Check
Twelve possible reasons Facebook ad costs rise, from auction pressure and campaign structure to tracking errors and unauthorized activity.
AdFence Team
Someone Is Running Ads on Your Facebook Account: Do This Now
Immediate steps to preserve evidence, stop unfamiliar Meta campaigns, review account access, and report unauthorized advertising activity.
AdFence Team
How Ad Accounts Get Hacked: Five Common Attack Paths
Five common routes into advertising accounts: infostealers, phishing, malicious app access, stale permissions, and credential stuffing.
AdFence Team