If you run Google Ads, or you let an agency run it for you, there is a new lock on the door. Since July 15, 2026, Google Ads requires a passkey to complete certain sensitive actions in your account. This is the Google Ads passkey requirement, and if the person who needs to change your billing or add a user has not set one up, they simply will not be able to. Most of the coverage filed this under account security. For anyone spending real money each month, it is an access story, and one with a timing trap worth understanding before it catches you.
What Google actually changed
One thing, narrowly. Google is not forcing a passkey on every login. You can still sign in with your password and 2-Step Verification as before. What now needs a passkey is a short list of high-risk operations. Google's own help documentation names adding new users, changing billing information, account linking updates and user access changes as the actions that require passkey verification. Google's FAQ puts it plainly: if a passkey is not created, you will not be able to complete sensitive actions in the Google Ads account.
A passkey is a credential tied to a device you physically control, unlocked with a fingerprint, a face scan or a screen-lock PIN. It cannot be typed, shared or phished the way a password and a one-time code can. That is the entire point. Google's stated reason is the wave of account hijacking that has hit advertisers, where an attacker with a stolen password relinks an account or changes billing before anyone notices, a pattern documented across the industry through the first half of 2026.
The part that bites agencies and multi-user accounts
Here is where it gets practical. A passkey is personal. It is bound to one person's device and cannot be shared across a team. Google states directly that passkeys are not compatible with shared agency logins, and that this is a technical limitation rather than a policy choice. If your account is run through a single shared login, that model breaks the first time someone needs to change billing or link a new account.
Google's own guidance is to move to individual access: invite each person who needs it with their own email address, and have each of them secure it with their own passkey. If your team uses a single sign-on platform like Okta, that does not get you out of it. Google confirms a Google passkey is still required for sensitive actions in Ads, on top of your normal SSO login.
The delay that turns a five-minute task into a week
This is the trap. You cannot create a passkey in the moment you need it and use it straight away. Google's documentation states a new passkey takes about one to two days to pair with Google Ads. Separately, Google notes a new passkey may be subject to a security delay of up to seven days before it can authorise sensitive tasks, and its troubleshooting guidance tells users to wait 48 hours after setup before authorising things like billing or permission changes.
Read those together and the lesson is simple. If your card fails on a Friday and nobody on the account has an active, paired passkey, you may not be able to fix billing that day, or even that week. For an account spending four or five figures a month, a paused account over a payment glitch is not a security feature. It is lost revenue while the delay clock runs. The fix is to set the passkey up now, while nothing is on fire.
What to do about it this week
Four actions, none of which cost anything.
First, set up a passkey today for everyone who touches billing or access. In Google Account settings, open Passkeys and security keys, then Create a passkey, and follow the device prompts. Do it on a personally owned device with a screen lock, not a shared machine. Then leave it to pair before you rely on it.
Second, check who is actually covered. In Google Ads, open the Admin menu, then Access and security, and read the Passkey status column. It shows enabled or disabled for every user in the account. Filter for the people showing disabled and chase them down before, not after, you need a sensitive change.
Third, fix shared logins before they fail. If your account or your agency still runs on one shared email, split it into individual users now. This is overdue for accountability reasons anyway, and the passkey rule makes it non-optional for any sensitive change.
Fourth, mind the device details. Google notes that autogenerated passkeys on Android cannot verify sensitive actions, and that Android browsers cannot complete these challenges at present. So do not assume an Android-only setup has you covered. Make sure at least one person has a working passkey on a supported device and browser.
The wider pattern
This is not a one-off. It lands in the same stretch of July that Google put a six-month limit on policy appeals, another quiet change to how accounts are governed rather than how ads perform. The theme is consistent: Google is tightening the operational plumbing of your account, and the advertisers who get caught out are the ones treating the platform as set-and-forget.
The honest summary
For a well-run account this is a twenty-minute chore that leaves you safer. For an account on a shared login with nobody enrolled, it is a landmine waiting for the day you need to move fast. The difference is entirely in whether you handle it before or after something breaks.
If you are not sure how your account access is structured, who can change billing, whether logins are shared, whether anyone is enrolled, that is one of the things our free 15-point Profit Audit checks, alongside your tracking, your audience structure and whether your reported numbers hold up against your actual sales. You keep the findings either way.